{"id":8028,"date":"2024-06-24T00:45:50","date_gmt":"2024-06-24T00:45:50","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=8028"},"modified":"2024-09-05T00:41:39","modified_gmt":"2024-09-05T00:41:39","slug":"microsoft-sentinel","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/microsoft-sentinel","title":{"rendered":"Microsoft Sentinel"},"content":{"rendered":"\n<p><a href=\"https:\/\/pariswells.com\/blog\/research\/microsoft-sentinel-pricing\">https:\/\/pariswells.com\/blog\/research\/microsoft-sentinel-pricing<\/a><\/p>\n\n\n\n<p>Create a new Log Analytics workspace because you probably have all your logs everywhere<\/p>\n\n\n\n<p>Enable Sentinel On Logs Analytics<\/p>\n\n\n\n<p>Choose Common for SecurityLogs<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-7.png\"><img loading=\"lazy\" decoding=\"async\" width=\"872\" height=\"338\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-7.png\" alt=\"\" class=\"wp-image-8116 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-7.png 872w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-7-300x116.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-7-768x298.png 768w\" sizes=\"auto, (max-width: 872px) 100vw, 872px\" \/><\/a><\/figure>\n\n\n\n<p>Install Connectors for everything you have<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-11.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"617\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-11-1024x617.png\" alt=\"\" class=\"wp-image-8029 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-11-1024x617.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-11-300x181.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-11-768x463.png 768w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-11.png 1476w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>Cloudapps<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"395\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8-1024x395.png\" alt=\"\" class=\"wp-image-8118 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8-1024x395.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8-300x116.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8-768x296.png 768w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8-1536x592.png 1536w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/07\/image-8.png 1587w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>Turn on the UEBA feature<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-13.png\"><img loading=\"lazy\" decoding=\"async\" width=\"993\" height=\"461\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-13.png\" alt=\"\" class=\"wp-image-8031 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-13.png 993w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-13-300x139.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-13-768x357.png 768w\" sizes=\"auto, (max-width: 993px) 100vw, 993px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-16.png\"><img loading=\"lazy\" decoding=\"async\" width=\"831\" height=\"842\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-16.png\" alt=\"\" class=\"wp-image-8036 img-responsive\" style=\"width:840px;height:auto\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-16.png 831w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-16-296x300.png 296w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-16-768x778.png 768w\" sizes=\"auto, (max-width: 831px) 100vw, 831px\" \/><\/a><\/figure>\n\n\n\n<p>Setup Enrichment Services : <a href=\"https:\/\/hacknowledge.com\/blog-post\/part1-new-microsoft-sentinels-enrichment-widget-in-ueba-module\/\">[Part1] New Microsoft Sentinel\u2019s Enrichment Widget in UEBA Module \u2013 Hacknowledge<\/a><\/p>\n\n\n\n<p>Import Bulk Analytics<\/p>\n\n\n\n<p> <a href=\"https:\/\/github.com\/MSSAPSCA1\/Azure_Sentinel\">GitHub &#8211; MSSAPSCA1\/Azure_Sentinel: Bulk turn on Analytic rules in Azure Sentinel<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/garybushey\/AzSentinelAnalyticsRules\">GitHub &#8211; garybushey\/AzSentinelAnalyticsRules: PowerShell commands to export the Azure Sentinel Rule Templates to a CSV and to create the Rules from selected entries in the CSV file<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/SecureHats\/SecureHacks\/tree\/main\/scripts\/Azure\/Sentinel\/Enable-AlertRules\">SecureHacks\/scripts\/Azure\/Sentinel\/Enable-AlertRules at main \u00b7 SecureHats\/SecureHacks \u00b7 GitHub<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"478\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25-1024x478.png\" alt=\"\" class=\"wp-image-8282 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25-1024x478.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25-300x140.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25-768x359.png 768w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25-1536x717.png 1536w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/06\/image-25.png 1857w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/pariswells.com\/blog\/research\/microsoft-sentinel-pricing Create a new Log Analytics workspace because you probably have all your logs everywhere Enable Sentinel On Logs Analytics Choose Common for SecurityLogs Install Connectors for [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8028","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/8028","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=8028"}],"version-history":[{"count":7,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/8028\/revisions"}],"predecessor-version":[{"id":8283,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/8028\/revisions\/8283"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=8028"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=8028"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=8028"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}