1,104 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer

Microsoft Sentinel Log integrity and non-repudiation

I have a question about Microsoft Sentinels Log integrity and non-repudiation properties of audit logs. For Example SPLUNK uses Bucket hashing to protect it's logs. Does Sentinel via Azure have any such protection, or can anyone shed light on how the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-09-03T12:09:04.5066667+00:00
Darren Hughes 0 Reputation points
commented 2024-09-03T15:47:13.3666667+00:00
Clive Watson 6,271 Reputation points MVP
1 answer

How to ingest logs in sentinel from azure cross-tenants resources? Such as Azure diagnostic, AAD etc.

I need to ingest logs from my organization cross-tenant resources into our primary tenant where we've centralized Sentinel as a SIEM. My Microsoft partner said i cannot use lighthouse option as my organisation is not a MSP. Can someone please in brief…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-09-03T09:43:36.62+00:00
Ajhar Hussain 0 Reputation points
answered 2024-09-03T13:12:40.63+00:00
Clive Watson 6,271 Reputation points MVP
1 answer

How to integrate Entitle withe Sentinel

Hi Team, I wanted to integrate Entitle with Sentinel, but I noticed that there is no built-in connector for Entitle in Sentinel by default. After speaking with the Entitle support team, they informed me that Entitle uses webhooks for integration. Could…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-09-02T09:34:19.42+00:00
Ali Salem Panah 0 Reputation points
answered 2024-09-03T09:33:20.6966667+00:00
Clive Watson 6,271 Reputation points MVP
0 answers

The syslog log cannot be sent to sentinel, and the AMA status is normal

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-09-03T08:18:13.24+00:00
Rong Ye 0 Reputation points
edited a comment 2024-09-03T09:27:18.03+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
1 answer

Microsoft Sentinel - Data Connector is showing as disconnected but is sending logs.

Hello everyone. I have a client that has both the 'Common Event Format via Legacy Agent' and 'Common Event Format via AMA' Data Connectors in their Microsoft Sentinel environment. Both are sending logs to the 'CommonSecurityLog' table, but oddly the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-26T16:50:10.22+00:00
Matthew Agosta 0 Reputation points
answered 2024-09-03T05:45:34.6366667+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

How to Parse/Extract data that is in 'SyslogMessage' field in MS Sentinel ?

I have recently integrated and ingested Syslog data to MS Sentinel. Unfortunately there is a field named "SyslogMessage" that appears to be NOT parsed. How do I parse the data that is in "SyslogMessage" field and turn them into…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2022-01-10T20:23:16.43+00:00
AzureSent-0127 41 Reputation points
edited the question 2024-09-03T02:54:45.5133333+00:00
Yan Xie 40 Reputation points Microsoft Employee
0 answers

Managing Customer Sentinel through Azure Lighthouse

Hi Experts, Please help. I have registered our customer on our Azure Lighthouse. I can see their Sentinel with data in it, but when I try to check data connectors, I am getting below errors: Can't see any connector connected, but when customer Global…

Azure Lighthouse
Azure Lighthouse
An Azure service that provides secure managed services and access control for partners and customers.
75 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-31T06:52:45.7733333+00:00
Naveen Sharma 20 Reputation points
0 answers

How to fix error when creating Sentinel-All-In-One MS Azure deployment

When attempting to create MS Azure Sentinel-All-In-One deployment, I get an error message for the enableSolutionsAndAlerts resource. The provided script failed with the following error: Microsoft.PowerShell.Commands.HttpResponseException: Response…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-28T05:27:14.0766667+00:00
Keith 0 Reputation points
edited a comment 2024-08-30T17:23:04.12+00:00
Keith 0 Reputation points
1 answer

Subscription field is not available in Microsoft Sentinel All-In-One in Azure

I'm getting "No Items available" when attempting to deploy Microsoft Sentinel All-In-One in Azure account? Under the Basic tab, the Subscription field is a mandatory field. It should load my Primary account, but nothing comes up.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-28T03:23:25.04+00:00
Keith 0 Reputation points
edited an answer 2024-08-30T07:35:40.5033333+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
1 answer

Enabling UEBA

dears i am trying to enable UEBA in my sentinel nut i am facing an issue when validating the data source as follow : where i have all necessary permissions. can anybody help me. Thanks

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-27T10:26:38.0333333+00:00
Firas Aqel 0 Reputation points
answered 2024-08-30T07:18:35.9466667+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
0 answers

Estamos com problemas em um Playbook, que realiza uma automação para o Sentinel

Estamos com problemas em um Playbook, que realiza uma automação para o Sentinel: Objetivo: Adicionar um ou mais IPs do incidente em uma named location Problema: - Em uma das etapas de GET de HTTP, o logic apps aponta o erro "required scopes are…

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
1,230 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-29T17:28:32.88+00:00
Marcos Guedes 0 Reputation points
2 answers

SecurityEvent Table Transformation DCR not working

I'm having an issue with ingestion on to a Workspace that is connected to Microsoft Sentinel. I have created a Transformation DCR / Ingestion Time Filter on the SecurityEvents table, but am still seeing events in the logs that should have been filtered…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-09T18:36:16.23+00:00
Greg Sneed 20 Reputation points
commented 2024-08-29T16:14:20.65+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
0 answers

Ingestion of AWS CloudWatch data to Microsoft Sentinel using S3 connector

Hello everyone, I want to integrate CloudWatch logs to S3 bucket using Lambda function and then to send those logs to Microsoft Sentinel. As per Microsoft documentation provided: Ingest CloudWatch logs to Microsoft Sentinel - create a Lambda function to…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-28T13:20:31.66+00:00
Vasilije Djurovic 66 Reputation points
edited a comment 2024-08-29T13:29:27.3833333+00:00
Vasilije Djurovic 66 Reputation points
0 answers

How to export Microsoft Sentinel logs

I'm trying to export Microsoft Sentinel logs and insights to Palo Alto XSIAM, so I need to know if there's any configuration I need to do on Microsoft Sentinel or any functionality that needs to be enabled on Sentinel for this integration to be seamless.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-26T12:14:30.4366667+00:00
Abbas Adeyinka Olasupo 0 Reputation points
commented 2024-08-29T10:36:21.6833333+00:00
Sandeep G-MSFT 18,041 Reputation points Microsoft Employee
2 answers

How do I disconnect Data connectors in sentinel?

I'm trying to remove data connectors from the microsoft sentinel tab. The data connectors that are giving me issues are ones that are still "ingesting" data, but there is no data collector rule attached to them. They are being collected through…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-23T19:14:08.1733333+00:00
Khalid Alkazak 5 Reputation points
edited a comment 2024-08-29T06:42:44.25+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
1 answer

ama agent installation vs arc agent install?

Hi there, There are 2 procedures for installing the Azure AMA agent for use with Sentinel as a syslog collector: install the AMA agent using the python script provided by Sentinel: …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-27T20:03:16.6766667+00:00
David Broggy 5,716 Reputation points MVP
answered 2024-08-29T05:19:49.5666667+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
0 answers

I am getting this error ?"Connectivity check failed: Status code:S3B40023, Message: An Access Denied exception occurred when attempting to download a S3 object - bucket cloudtrail-s3-xxxxxx-xxx-xx. Ensure the S3has the specified permissions in its"PERMI""

Hello All, We were working on ingesting logs in sentinel using aws s3 connector. After the connection was made successfully, I workied fine and we were able to see the logs. But today we stopped getting the logs, When i run the health command, got this…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-23T18:20:35.56+00:00
Karan Prabhakar 0 Reputation points
commented 2024-08-28T08:48:56.8466667+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
0 answers

how to use data transformation on the SecurityEvent table in Sentinel to drop events

Hi there, I'd like to use a data transformation to filter some events entering Sentinel. The test I'm doing is with the SecurityEvent table. I added this transformation: source| where EventID <> 4688 However after waiting an hour I'm still seeing…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
asked 2024-08-23T15:29:04.7333333+00:00
David Broggy 5,716 Reputation points MVP
commented 2024-08-28T08:35:09.6733333+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
1 answer

Defender for Endpoint log retention

Hi there, In order to increase data retention for CloudAppEvents or DeviceRegistryEvents tables i know we can ingest them in Microsoft Sentinel. My question is if there is another way to store these logs? I just want to retain the logs for cold storage…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
38 questions
asked 2024-08-27T11:01:19.6966667+00:00
Luís Costa 206 Reputation points
answered 2024-08-28T05:54:25.0133333+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee
2 answers

Not able to ingest a logs from Microsoft Exchange and Microsoft Defender XDR

Hey I have deployed the Microsoft Sentinel and are able to be getting some logs from signing logs. But a want a log for my cloud apps and for that. I have installed the Microsoft defender XDR connector. it is connected successfully but when I checked…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,335 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,104 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
135 questions
asked 2024-08-21T19:39:24.9066667+00:00
Robin Jha 0 Reputation points
answered 2024-08-27T05:29:32.5133333+00:00
Givary-MSFT 32,116 Reputation points Microsoft Employee