Configure SIEM security operations using Microsoft Sentinel

Intermediate
Security Operations Analyst
Azure
Microsoft Sentinel
Azure Log Analytics

In this module, you learned how to configure SIEM security operations using Microsoft Sentinel.

Learning objectives

Upon completion of this module, the learner is able to:

  • Create and configure a Microsoft Sentinel workspace
  • Deploy Microsoft Sentinel Content Hub solutions and data connectors
  • Configure Microsoft Sentinel Data Collection rules, NRT Analytic rule and Automation
  • Perform a simulated attack to validate Analytic and Automation rules

Prerequisites

  • Basic experience with Azure services
  • Basic knowledge of operational concepts, such as monitoring, logging, and alerting
  • An Azure subscription