KQL - extract values from SyslogMessage - How to?
Hello, I want to extract some information from a SyslogMessage in KQL. Let's assume i have the following Syslog Message: "002E0102","A":"002E","O":"NetIQ Access Manager\nidp" I managed to…
Arc Private Link Scope and AMPLS
Has anyone had any luck getting logs sent over AMPLS to Sentinel with the Security Events via AMA connector? I have tested and validated DNS entries on my Arc servers, but I despite the DCR being up and AMPLS being fully configured I am still not…
App center -> Application Insights export getting auto disabled
For mobile app has app centre analytics integrated and export was enabled to azure Application Insights. Often this setting getting disabled automatically result in data lost on application insights. How to determine the root cause?
KQL - what does @ stand for in regex extraction
Hello, I want to extract some data from a SyslogMessage and i'm doing fine with the following Syslog | where SyslogMessage contains '<EPOevent>' or ProcessName contains 'EPOEvents' | extend EPO_Thread_ID =…
Country Specific Reports in Microsoft 365 Defender Portal (Security.microsoft.com)
Is it possible to generate reports highlighting security trends (Identity, Data, Devices and Apps) for a company that has presence in various countries using Microsoft 365 defender or a similar product. I will appreciate ideas..
Microsoft learn eductor center
How to earn Reputation points
What is the Diffrent Between Data Connecters and Contect Hub Microsoft Sentinel
Hello, i need to add Cisco Umbrella, but i can see there plug in Data Contender and Content Hub so i would like to know What is the Different
Does sentinel have a sub playbook/ combine two playbook mechanisms or not?
We are creating an azure logic app and we need to call one playbook from another playbook. So can we call one playbook from another playbook and pass input parameters to the second playbook? Also is it allowed to return a response back to calling…
How to use Polling in Azure sentinel Playbook
We have to implement a functionality in the azure logic app in which we need to wait till one API call gets completed and during that time we need to poll the status of that process periodically using another API call. Also we have a condition on which…
OMS Agent (CEF) w/ Private Link
Is it possible to send CEF logs over Private Link to workspace my Sentinel uses? I currently have a log forwarder (OMS Agent) in Azure for my remote firewalls and one at my HQ (where my ExpressRoute is located). I want to send the logs at the HQ over…
why this cron expression is not working in my azure function app ?
I have created three timer trigger function apps with below cron expression for each function apps on 26th May 2022 and it was working perfectly. 1st cron expression --> 0 0 * * * * -------> run every hour like 1,2,3,4,... 2nd…
Have all the decals moved؟
I want to make sure the badges are transmitted
microsoft loginproblem
I am using Microsoft authentication to authenticate my portal user, I integrate Microsoft authentication with my Django project and I successfully redirect my user to Microsoft login screen but when I enter user credentials it appears (…
Getting error while trying to deploy Sentinel DATP connector
When i try and deploy the DATP connector using either ARM template or Powershell script, I receive the below error message { "code": "DeploymentFailed", "message": "At least one resource deployment…
Is there a table to know what data type a Logic app dynamic content is for Sentinel?
I am working on connecting my Sentinel solution to SNOW. I'm running into an issue whenever I select a value that has an Array. Once the For each control kicks in, the Logic App fails after adding a Second Array. Example: Added Sentinel…
Link to upload Microsoft Edge
Can you please send me the link to upload Microsoft edge ?
Two Microsoft Defender for Identity Alerts Missing Content
Hello, Two Defender for Identity alerts that we get regularly come in with almost no information. We believe there is something wrong with the sensor but don't have visibility on it. Account enumeration reconnaissance (on one endpoint) …
Integrate Syslog data connector in Sentinel
Hi Team, Could please help steps in details to integrate the syslog data connector in sentinel. Regards, Ravi Teja
Tea!ms connection failure!
Hello! Depuis quelques jours je n'arrive pas à me connecter à mon compte teams :il s'affiche code d'erreur contacter votre orgainzation ....
Azure Solution for Streaming Logs - SIEM
Hello, I am planning to use Azure sentinel for my on-premises and cloud workloads/devices. Like any other SIEM solution, Sentinel requires you to have a log collector where all the devices(Syslog,CEF) can send the logs and than they are transported…