1,210 questions with Microsoft Sentinel tags

Sort by: Updated
0 answers

Can I connect a webhook from an external cloud platform to an Azure Durable Function app deployed in a private network?

We have a usecase to deploy azure durable function app(HTTPStarter based) in private network and then provide its access endpoint to the webhook configuration in another product's cloud instance. So, is it possible to send data to azure durable app…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
5,350 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-20T12:18:07.0733333+00:00
Nirali Shah 146 Reputation points
commented 2025-01-27T02:21:33.4533333+00:00
Shireesha Eeraboina (Quadrant Resource LLC) 830 Reputation points Microsoft Vendor
0 answers

Integrating MDC, Sentinel and Azure monitor with ServiceNow

I want to integrate MS sentinel, MDC, & Azure Monitor with ServiceNow tool. the ServiceNow team has used/created the domain separation in the ServiceNow. In the sentinel integration document, it has been mentioned that domain separation is not…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,428 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,472 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-22T06:58:47.3633333+00:00
Brynel Peter Libera (CONVERGYS CORPORATION) 40 Reputation points Microsoft Vendor
commented 2025-01-27T01:52:41.2466667+00:00
Rahul Podila 1,395 Reputation points Microsoft Vendor
1 answer

How to send Windows logs from an on premises windows machine to Microsoft Sentinel?

Hi, I'm trying to set up Microsoft Sentinel, and I need to forward windows logs from all of our machines. I'm experimenting with the configuration on a machine running Windows 11 Pro, then plan to copy the configuration across the rest of our machines.…

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,741 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-21T21:40:59.6366667+00:00
Colin R 0 Reputation points
answered 2025-01-23T21:01:19.7833333+00:00
Akhilesh Vallamkonda 11,355 Reputation points Microsoft Vendor
1 answer

Tasks-Details of the Tasks missing in SecurityIncident table

The Tasks added to an Incident don't have the Details (text added to the Task except the Title) in the SecurityIncident table or any other Table. Where can we find these details?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2024-12-28T21:12:16.1766667+00:00
Grace A 1 Reputation point
commented 2025-01-23T08:38:19.7633333+00:00
Pauline Mbabu 590 Reputation points Microsoft Employee
2 answers

Conditional access triggered after unsuccessful password?

Hello, We had a situation that for all sign ins password was invalid while conditional access were triggered and eventually sign in was blocked with information that it was blocked by conditional access policies. Is it possible that unsuccessful first…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,996 questions
asked 2025-01-21T14:45:41.48+00:00
Justyna K 5 Reputation points
commented 2025-01-22T15:08:11.49+00:00
Raja Pothuraju 11,515 Reputation points Microsoft Vendor
0 answers

Data Connector - Api Restriction

Dear Prisma Cloud Support Team, I am experiencing an issue with the integration between Microsoft Sentinel and Prisma Cloud using the Data Connector described in your documentation (Integrating Prisma Cloud with Azure Sentinel using the Data…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-22T12:16:32.56+00:00
Jakub Wierzchowski 0 Reputation points
0 answers

Microsoft Sentinel: System Assigned Managed Identity can't find location

I'm trying to connect Azure Activity to Microsoft Sentinel. It requires creating a Managed Identity. When creating a System Assigned Managed Identity, a location is required but there's no location options to select. Any idea what could be causing this?…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-10T15:58:49.0066667+00:00
alfalfa 5 Reputation points
edited a comment 2025-01-22T11:51:52.7333333+00:00
Vivek Gajera 0 Reputation points
1 answer

Has anyone tried correlating Prisma threat logs with Microsoft Events before?

We are trying to correlate our threat logs with any Microsoft events that could be related to it. It would help us enrich the alerts. Has anyone done it before? Does Microsoft have templates on it? Our current setup is, we have custom threat logs from…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-16T04:16:31.1666667+00:00
Vince Ian Cruz 0 Reputation points
answered 2025-01-21T13:21:56.6866667+00:00
Andrew Blumhardt 9,866 Reputation points Microsoft Employee
2 answers

Summary rules - Limit on total aggregated size

Folks, I'm trying to use summary rules to aggregate firewall logs. There's a hard size limit from MS per result of 100 MB which I think is not up to the mark for firewall logs. While summarizing I'm creating two sets and grouping by 7 other fields (I…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2024-12-19T14:16:00.4066667+00:00
Khanna, Keshav 20 Reputation points
answered 2025-01-21T09:16:17.3133333+00:00
Prathista Ilango 170 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

AWS GuardDuty integration Issue with Sentinel

Hi Support Team I wanted to integrate GuardDuty with Sentinel, so I followed the instructions in this link my connector is connected successfully, but I am still not receiving any logs in the AWSGuardduty table in Sentinel. would you please someone tell…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-15T12:56:11.94+00:00
Ali Salem Panah 40 Reputation points
commented 2025-01-21T09:02:45.42+00:00
Givary-MSFT 35,131 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Unable to leverage Auxiliary log table with Text or Json ingestion

Hi, I have followed all the steps from this article https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-collection-log-text?tabs=portal , and am able to ingest data into 'basic' logs. However if I try to use an 'Auxiliary' log table as…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,428 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2024-11-22T17:24:34+00:00
Mehboob Ahmad 25 Reputation points
edited a comment 2025-01-20T04:41:31.54+00:00
Manisha 0 Reputation points
1 answer One of the answers was accepted by the question author.

How to connect Azure Activity data connector in Sentinel

Hello, I am having trouble connecting the Data Connectors in Sentinel. The instructions in Microsoft Learn differ from what I observe in Sentinel, but here is what I have done thus far: I have installed the Azure Activity Data Connector from the Content…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-10T20:39:41.94+00:00
Ty 20 Reputation points
commented 2025-01-20T02:48:02.29+00:00
Ty 20 Reputation points
1 answer

Integrate Azure Purview to Azure Sentinel

Hello, I would like to integrate my Azure Purview with Azure Sentinel. I have followed the steps described in the official documentation at this "https://learn.microsoft.com/en-us/purview/register-scan-azure-blob-storage-source" link. However,…

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,355 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-15T03:24:53.6266667+00:00
Muhammad Rifqi Prasetyo 0 Reputation points
commented 2025-01-17T08:08:16.88+00:00
Smaran Thoomu 19,310 Reputation points Microsoft Vendor
0 answers

How to find out which of several authenticators was used in a sign-in?

We are using MFA with Microsoft Authenticator for user sign-ins to our tenant. Many of our users have registered more than one Microsoft Authenticator instance. Sometimes this is deliberate, in order to have a backup in case the primary smartphone is…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,996 questions
asked 2025-01-13T13:20:23.8366667+00:00
Tilman Schmidt 50 Reputation points
commented 2025-01-16T16:53:22.88+00:00
Tilman Schmidt 50 Reputation points
1 answer

How do you stop duplicate CEF and Syslog entries with the new Azure Monitor Agent

Hi there, I have the new Azure Monitor Agent for Linux installed and have created and run the new Data Collection Rule set without issue. I now have CEF and Syslog coming through but want to filter out CEF from Syslog. In /etc/rsyslog.d I created a new…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2023-09-14T14:29:40.56+00:00
Lloyd Carnie 5 Reputation points
commented 2025-01-16T03:14:11.3266667+00:00
Roger Spraggon 0 Reputation points
1 answer One of the answers was accepted by the question author.

Disable pop-ups in Azure Sentinel

Hello, I’ve been working with Azure Sentinel for about a year now. Some months ago, Azure introduced a pop-up that appears whenever I have a KQL query open and attempt to close the browser tab or press X. This has become extremely frustrating. I simply…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-04T06:14:30.7033333+00:00
Albert Hardvendel 20 Reputation points
accepted 2025-01-11T06:28:46.48+00:00
Albert Hardvendel 20 Reputation points
1 answer

Netskope Data Connector (using Azure Functions) Disconnected

Upon completion of all the configurations provided and making sure Netskope API token is valid. The data connector is still disconnected. Tried running the Trigger playbook and it triggered successfully but still the connector is disconnected.

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
5,350 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-10T02:56:44.5466667+00:00
Reigan Arcilla 0 Reputation points
answered 2025-01-10T06:06:49.3533333+00:00
Raja Pothuraju 11,515 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Defender for Endpoint Vulnerability Management Browser Extensions not populating

We recently started a trial of the Defender Vulnerability Management add-on and applied the licenses to our users. Everything seems to be working fine, but unfortunately on a small handful of the browser extensions and hardware information are…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,472 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
167 questions
asked 2025-01-07T21:04:33.3333333+00:00
George Zerphey 176 Reputation points
accepted 2025-01-08T13:33:50.9333333+00:00
George Zerphey 176 Reputation points
1 answer One of the answers was accepted by the question author.

can we able to transfer the security event logs of windows server of one resource group to an log analytics workspace (Microsoft Sentinel) which is deployed with other resource group

can we able to transfer the security event logs of windows server of one resource group to an log analytics workspace (Microsoft Sentinel) which is deployed with other resource group

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2025-01-07T14:49:37.18+00:00
K, Chandrashekharmurthy 20 Reputation points
accepted 2025-01-08T13:18:14.6066667+00:00
K, Chandrashekharmurthy 20 Reputation points
1 answer

How to integrate paloalto firewall on-premises and cloud with Microsoft sentinel step by step

How to integrate paloalto firewall on-premises and cloud with Microsoft sentinel step by step

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
asked 2024-12-15T09:21:08.1633333+00:00
suraj hirekudi 0 Reputation points
commented 2025-01-02T09:42:01.0933333+00:00
Givary-MSFT 35,131 Reputation points Microsoft Employee