ama agent installation vs arc agent install?
Hi there, There are 2 procedures for installing the Azure AMA agent for use with Sentinel as a syslog collector: install the AMA agent using the python script provided by Sentinel: …
I am getting this error ?"Connectivity check failed: Status code:S3B40023, Message: An Access Denied exception occurred when attempting to download a S3 object - bucket cloudtrail-s3-xxxxxx-xxx-xx. Ensure the S3has the specified permissions in its"PERMI""
Hello All, We were working on ingesting logs in sentinel using aws s3 connector. After the connection was made successfully, I workied fine and we were able to see the logs. But today we stopped getting the logs, When i run the health command, got this…
how to use data transformation on the SecurityEvent table in Sentinel to drop events
Hi there, I'd like to use a data transformation to filter some events entering Sentinel. The test I'm doing is with the SecurityEvent table. I added this transformation: source| where EventID <> 4688 However after waiting an hour I'm still seeing…
Not able to ingest a logs from Microsoft Exchange and Microsoft Defender XDR
Hey I have deployed the Microsoft Sentinel and are able to be getting some logs from signing logs. But a want a log for my cloud apps and for that. I have installed the Microsoft defender XDR connector. it is connected successfully but when I checked…
Sentinel to Jira intergration
Hi team, Currently i am working on sentinel to jira integration, i couldn't find any better documentation for the process. Iam focusing on this for Auto-creation of tickets in Jira for incidents generated in Sentinel. Bi-directional sync for assigned…
Do Defender for Endpoint license pricing differ whether the endpoint is a server or a client machine?
Do Defender for Endpoint license pricing differ whether the endpoint is a server or a client machine?
AWS S3 bucket logs not ingesting to Microsoft Sentinel
I have configured the AWS S3 data connector in Microsoft Sentinel. Ref: https://video2.skills-academy.com/en-us/azure/sentinel/connect-aws?tabs=s3. I have created a S3 bucket and Simple queue service as documented on the connector page. Furthermore, I have…
Data Connector to enable bidirectional sync between Microsoft Sentinel and Jira Service Management
Hi Team, Are there plans to make available a data connector to enable bidirectional sync between Microsoft Sentinel and Jira Service Management? It would be great to have the following features available for this connector: Auto-creation of tickets…
Explain how Defender for Endpoint alerts are combined into incidents
Hi there, In the Defender portal (Security.microsoft.com) you can see your Defender for Endpoint Incidents. Here's how I think Incident IDs work when alerts combine with other Incidents. Please correct me if I'm wrong and please suggest a link to…
Issue with Sentinel Entra ID Connector
Hello, We have a Log Analytics Workspace that was moved to a different Azure subscription. One of the connectors that is configured is for Entra ID. I'm able to confirm that we're receiving Entra ID logs, but we've found an issue when trying to access…
Incorrect data in the Usage table
Hi folks A few days ago I noticed an odd behavior in multiple environments. In these Sentinel instances we don't have any logs in the AzureDiagnotics table. But when I query the Usage table it shows some data for the AzureDiagnostics DataType. So,…
Mapping AWS CloudTrail log schema to Sentinel table columns
Is there a predefined mapping between the AWS CloudTrail log schema and the Sentinel table columns? Specifically, can you provide the schema mapping via the AWS S3 data connector?
Anyone managed to get IoCs ( threat indicators ) from Sentinel to Defender for endpoint
Currently I have some scripts running on a cron job that import IoCs to defender for endpoint indicator list ( this allows blocking on the endpoints) . We have recently setup a Sentinel instance and it’s pretty easy to add threat intel to Sentinel via a…
Need Cisco Meraki firewall logs on sentinel
Want to get Cisco Meraki firewall logs on sentinel.Kindly anybody share a complete flow either in terms of documentation or as available. Becuse after searching alot still unable to find proper guidence. to configure meraki firwall logs on microsoft…
How to connect the Microsoft Defender XDR event logs using the API?
I'm currently working on a project to fully automate the deployment of a Microsoft Sentinel workspace. I already developed a working PowerShell script that uses the Microsoft.SecurityInsights API to install solutions from the content hub and enable the…
How to connect the Microsoft Defender XDR event logs using the API?
I'm currently working on a project to fully automate the deployment of a Microsoft Sentinel workspace. I already developed a working PowerShell script that uses the Microsoft.SecurityInsights API to install solutions from the content hub and enable the…
How to connect the Microsoft Defender XDR event logs using the API?
I'm currently working on automating the deployment of a Microsoft Sentinel workspace using PowerShell scripts. So far, I have successfully used the Microsoft.SecurityInsights API to install solutions and enable analytic rules. Now, I am looking to…
How to connect the Microsoft Defender XDR event logs using the API?
I'm currently working on a project to fully automate the deployment of a Microsoft Sentinel workspace. I already developed a working PowerShell script that uses the Microsoft.SecurityInsights API to install solutions from the content hub and enable the…
How to connect the Microsoft Defender XDR event logs using the API?
I'm currently working on a project to fully automate the deployment of a Microsoft Sentinel workspace. I already developed a working PowerShell script that uses the Microsoft.SecurityInsights API to install solutions from the content hub and enable the…
Jumpcloud connector not in sentinel
How can we connect it with sentinel, I tried solutions available on Github but it seems to be having an issue The Function app may be missing a module containing the 'New-AzStorageContext' command definition. If this command belongs to a module…