Can I connect a webhook from an external cloud platform to an Azure Durable Function app deployed in a private network?
We have a usecase to deploy azure durable function app(HTTPStarter based) in private network and then provide its access endpoint to the webhook configuration in another product's cloud instance. So, is it possible to send data to azure durable app…
Integrating MDC, Sentinel and Azure monitor with ServiceNow
I want to integrate MS sentinel, MDC, & Azure Monitor with ServiceNow tool. the ServiceNow team has used/created the domain separation in the ServiceNow. In the sentinel integration document, it has been mentioned that domain separation is not…
How to send Windows logs from an on premises windows machine to Microsoft Sentinel?
Hi, I'm trying to set up Microsoft Sentinel, and I need to forward windows logs from all of our machines. I'm experimenting with the configuration on a machine running Windows 11 Pro, then plan to copy the configuration across the rest of our machines.…
Tasks-Details of the Tasks missing in SecurityIncident table
The Tasks added to an Incident don't have the Details (text added to the Task except the Title) in the SecurityIncident table or any other Table. Where can we find these details?
Conditional access triggered after unsuccessful password?
Hello, We had a situation that for all sign ins password was invalid while conditional access were triggered and eventually sign in was blocked with information that it was blocked by conditional access policies. Is it possible that unsuccessful first…
Data Connector - Api Restriction
Dear Prisma Cloud Support Team, I am experiencing an issue with the integration between Microsoft Sentinel and Prisma Cloud using the Data Connector described in your documentation (Integrating Prisma Cloud with Azure Sentinel using the Data…
Microsoft Sentinel: System Assigned Managed Identity can't find location
I'm trying to connect Azure Activity to Microsoft Sentinel. It requires creating a Managed Identity. When creating a System Assigned Managed Identity, a location is required but there's no location options to select. Any idea what could be causing this?…
Has anyone tried correlating Prisma threat logs with Microsoft Events before?
We are trying to correlate our threat logs with any Microsoft events that could be related to it. It would help us enrich the alerts. Has anyone done it before? Does Microsoft have templates on it? Our current setup is, we have custom threat logs from…
Summary rules - Limit on total aggregated size
Folks, I'm trying to use summary rules to aggregate firewall logs. There's a hard size limit from MS per result of 100 MB which I think is not up to the mark for firewall logs. While summarizing I'm creating two sets and grouping by 7 other fields (I…
AWS GuardDuty integration Issue with Sentinel
Hi Support Team I wanted to integrate GuardDuty with Sentinel, so I followed the instructions in this link my connector is connected successfully, but I am still not receiving any logs in the AWSGuardduty table in Sentinel. would you please someone tell…
Unable to leverage Auxiliary log table with Text or Json ingestion
Hi, I have followed all the steps from this article https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-collection-log-text?tabs=portal , and am able to ingest data into 'basic' logs. However if I try to use an 'Auxiliary' log table as…
How to connect Azure Activity data connector in Sentinel
Hello, I am having trouble connecting the Data Connectors in Sentinel. The instructions in Microsoft Learn differ from what I observe in Sentinel, but here is what I have done thus far: I have installed the Azure Activity Data Connector from the Content…
Integrate Azure Purview to Azure Sentinel
Hello, I would like to integrate my Azure Purview with Azure Sentinel. I have followed the steps described in the official documentation at this "https://learn.microsoft.com/en-us/purview/register-scan-azure-blob-storage-source" link. However,…
How to find out which of several authenticators was used in a sign-in?
We are using MFA with Microsoft Authenticator for user sign-ins to our tenant. Many of our users have registered more than one Microsoft Authenticator instance. Sometimes this is deliberate, in order to have a backup in case the primary smartphone is…
How do you stop duplicate CEF and Syslog entries with the new Azure Monitor Agent
Hi there, I have the new Azure Monitor Agent for Linux installed and have created and run the new Data Collection Rule set without issue. I now have CEF and Syslog coming through but want to filter out CEF from Syslog. In /etc/rsyslog.d I created a new…
Disable pop-ups in Azure Sentinel
Hello, I’ve been working with Azure Sentinel for about a year now. Some months ago, Azure introduced a pop-up that appears whenever I have a KQL query open and attempt to close the browser tab or press X. This has become extremely frustrating. I simply…
Netskope Data Connector (using Azure Functions) Disconnected
Upon completion of all the configurations provided and making sure Netskope API token is valid. The data connector is still disconnected. Tried running the Trigger playbook and it triggered successfully but still the connector is disconnected.
Defender for Endpoint Vulnerability Management Browser Extensions not populating
We recently started a trial of the Defender Vulnerability Management add-on and applied the licenses to our users. Everything seems to be working fine, but unfortunately on a small handful of the browser extensions and hardware information are…
can we able to transfer the security event logs of windows server of one resource group to an log analytics workspace (Microsoft Sentinel) which is deployed with other resource group
can we able to transfer the security event logs of windows server of one resource group to an log analytics workspace (Microsoft Sentinel) which is deployed with other resource group
How to integrate paloalto firewall on-premises and cloud with Microsoft sentinel step by step
How to integrate paloalto firewall on-premises and cloud with Microsoft sentinel step by step