1,000 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

GitHub 500 internal server error

I'm attempting to install analytics via a GitHub repository and when I get to to the authorize step I get the following error. Operation name: Listrepositories Time stamp: Wed Aug 31 2022 08:32:50 GMT-0400 (Eastern Daylight Time) Event…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-31T13:30:41.877+00:00
George Zerphey 131 Reputation points
accepted 2022-08-31T19:11:34.137+00:00
George Zerphey 131 Reputation points
1 answer

Microsoft Azure Down

hi There, Is Microsoft Azure is down all over the region? https://status.azure.com/en-us/status May we know the root cause and the estimated timeline to recover? Thanks

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-30T12:26:48.47+00:00
Nafila Afrin 111 Reputation points
answered 2022-08-30T12:51:32.63+00:00
Nadav Ben Haim 496 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Deploying and managing Sentinel out-of-box content as code

Hello, Could anyone chime in with their approach to automating the deployment and management of Sentinel out-of-box content as code? Posted in January 2020 there is the Microsoft Sentinel Blog post by Javier Soriano, describing a community…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-15T14:38:12.44+00:00
kkoole 21 Reputation points
accepted 2022-08-30T08:31:49.677+00:00
kkoole 21 Reputation points
2 answers

Questions about microsoft sentinel ueba users

Do users have to be members of Azure Active Directory when using the microsoft sentinel UEBA feature? Can I use the logs of users of my other applications and related login information for UEBA analysis? If so how should I transfer my users to microsoft…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-24T09:22:51.743+00:00
Dy_fighting 1 Reputation point
answered 2022-08-26T10:53:30.83+00:00
Clive Watson 5,721 Reputation points MVP
1 answer

Is CEF connector with custom log file possible?

Hello, I am trying to configure CEF connector using a Linux VM as log forwarder. getting a folder of syslog in connected log analytic workspace instead of "CommonSecurityEvent". I am getting the data In that syslog table now…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-25T13:18:32.077+00:00
Jayesh Prajapati 1 Reputation point
commented 2022-08-26T05:55:47.01+00:00
Jayesh Prajapati 1 Reputation point
2 answers

WSUS :- MS office patches are not install

Using WSUS MS office patches are not install for some End Point system OS is Windows 10 21H2.Remaining security & all patch deployed. can help me is what issues

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,263 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-18T06:26:28.147+00:00
Aniket Subhash Pardeshi 1 Reputation point
commented 2022-08-25T09:00:43.533+00:00
Amandayou-MSFT 11,051 Reputation points
2 answers

Azure sentinel-Cisco ASA Parser

Hi There, We have onboarded CISCO ASA logs into sentinel using plain syslog server. Is there a way to onboard it via CEF syslog server or is there any parser available for CISCO ASA logs. The log format is linked below …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-23T02:27:55.88+00:00
Nafila Afrin 111 Reputation points
answered 2022-08-24T03:19:56.217+00:00
David Broggy 5,686 Reputation points MVP
1 answer

Log Analytics Agent for Linux fails to disable synchronization with "OMS_MetaConfigHelper.py --disable"

I have a Ubuntu 20.04.3 LTS server I configured to be a CEF log forwarder to Microsoft Sentinel for Cisco ASA(s). After installing the agent I tried to run the command to disable syslog from duplicating messages to Sentinel as noted in…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-01-28T21:36:51.397+00:00
AzureJoel 1 Reputation point
commented 2022-08-23T04:53:40.137+00:00
William Shead 1 Reputation point
1 answer One of the answers was accepted by the question author.

Azure Sentinel Workbooks (Dashboad) - distinct when chosen from the drop down

Hi team, I am preparing a dashboard that is built from 2 filters: the name of the application and the name of the user.  Is there a way to make it so when I select a user it will "distinct" all the applications related to that user?  …

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,798 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-22T07:41:09.063+00:00
Alon Keilin 141 Reputation points
accepted 2022-08-22T09:00:41.017+00:00
Alon Keilin 141 Reputation points
0 answers

Restore Purged MailRe

Can we restore purged mails which are purged using the command get-compliancesearchaction I have soft deleted the mails. Please let me know can we restore those mails.

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
625 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-20T08:39:00.53+00:00
Preeti Rani 1 Reputation point
1 answer One of the answers was accepted by the question author.

Network device discovery and vulnerability management : Supported OS

Hello, I would like to know if Microsoft Defender Vulnerability Management can discover Fortinet firewalls and scan associated vulns ? https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-devices?view=o365-worldwide …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-02T13:46:38.603+00:00
ESSID 21 Reputation points
accepted 2022-08-18T07:09:01.223+00:00
ESSID 21 Reputation points
2 answers

Join Sentinel Entity Json in Logicapp

Sentinel alert Entity output in Logicapp is in below format [ { "$id": "3", "Name": “randamuser1”, "Type": "account" }, { "$id": "4", …

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,896 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-14T05:42:36.047+00:00
Karthick G 101 Reputation points
answered 2022-08-18T04:54:50.56+00:00
MayankBargali-MSFT 69,421 Reputation points
1 answer

Auzure Service Health - Data in Microsoft Sentinel for SOC Service providers

Intro baseVISION provides SOC Services for customers. In the role of SOC provider, we should receive alerts if any Azure Services fails with regard to Security. We had to check every individual customer tenant for the following issue instead of…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-06-27T14:49:05.577+00:00
Jürg Meier 6 Reputation points
answered 2022-08-17T16:09:47.443+00:00
Clive Watson 5,721 Reputation points MVP
3 answers

invoking | summarize d= make_set(DeviceId) returning null values from API. If I convert make_set to tostring then results are appearing. | summarize d= tostring(make_set(DeviceId)) but the d is becoming string.

API details: https://api-eu.securitycenter.windows.com/api/advancedqueries/run KQL invoking | summarize d= make_set(DeviceId) returning null values from API. If I convert make_set to tostring then results are appearing. | summarize d=…

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-04T06:47:40.5+00:00
Balaji Thambisetty 1 Reputation point
answered 2022-08-17T09:50:56.257+00:00
Ian Xue (Shanghai Wicresoft Co., Ltd.) 31,091 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Sentinel Analytics Query Time Generated filter

Hi, When Sentinel Custom analytics query is built do we need to mention the time generated filter in query. E.g: If am writing a Custom analytics to Run query every 1 hour and look for data for last 1 hour do i still send to mention Time…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-07-29T06:47:45.77+00:00
Karthick G 101 Reputation points
accepted 2022-08-14T05:44:28.613+00:00
Karthick G 101 Reputation points
1 answer

While packaging solution in azure sentinel I am facing an error called InvalidOperation.

I want to publish one solution on sentinel and following official document, README.md Here while packaging that solution I am facing one error in between which is, getting this error while generating playbook template. Can anyone please…

Microsoft 365 Publishing
Microsoft 365 Publishing
Microsoft 365: Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line. Publishing: The process of preparing, producing, and releasing content for distribution or sale.
599 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-07-25T13:21:06.017+00:00
Bharvi Bhut 181 Reputation points
answered 2022-08-12T09:57:55.757+00:00
Humberto Marinho 1 Reputation point
1 answer

I am not able to schedule az 104 exam

Hi, My 104 certificate is expire d and I want to take the exam again. But, I am getting below error while scheduling the exam. 50080: Our records indicate that you have already taken this exam. You can only retake this exam if you previously…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-07-27T14:27:10.517+00:00
Rohit 1 Reputation point
answered 2022-08-12T02:57:47.097+00:00
Humberto Marinho 1 Reputation point
2 answers One of the answers was accepted by the question author.

KQL Query to verify diagnostic logs

Hello Folks If i set a diagnostic setting for example of a storage account , how can i verify the log is coming to sentinel in last few min or hrs . Usually we use Azure diagnostic and Azure activity then pipe to build a single query but i…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,858 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-10T00:10:10.273+00:00
Mohammed Altamash Khan 2,081 Reputation points
accepted 2022-08-10T17:49:26.267+00:00
Mohammed Altamash Khan 2,081 Reputation points
2 answers

Parsing multiline data in Sentinel

Hi, We are getting data into LogAnalytics in following format; One RaW logs has multiple lines in the log file and they repeat for each operations performed in the same log file Reverse date time = 487930544 Sequence number = 2147488705 …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-08T06:38:27.657+00:00
Gaurav Ramteke 1 Reputation point
commented 2022-08-09T05:47:04.883+00:00
GauravRamteke 1 Reputation point
0 answers

Why some of the column data is not posted to log analytics workspace though it is showing in logs of Azure Function App?

I have created a timer trigger function app that is ingesting data into Azure Log Analytics Workspace. while ingesting data I have printed the logs and it is showing the data that will be pushed to log analytics workspace the log is in below image. …

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
4,365 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,000 questions
asked 2022-08-02T07:24:42.927+00:00
Rushit Ajudiya 146 Reputation points
commented 2022-08-09T03:59:05.64+00:00
MayankBargali-MSFT 69,421 Reputation points