Skip to content

Commit 29d8d21

Browse files
committed
Update summary-rules-tutorial.md
1 parent 68d3391 commit 29d8d21

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

articles/sentinel/summary-rules-tutorial.md

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,12 +26,11 @@ This article provides an example of how to use summary rules to aggregate insigh
2626
2727
## Prerequisites
2828

29-
To create summary rules in Microsoft Sentinel:
30-
31-
- Microsoft Sentinel must be enabled in at least one workspace, and actively consume logs.
32-
33-
- You must be able to access Microsoft Sentinel with [**Microsoft Sentinel Contributor**](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) permissions. For more information, see [Roles and permissions in Microsoft Sentinel](roles.md).
29+
To complete this tutorial, you need:
3430

31+
- A Microsoft Sentinel-enabled workspace into which you actively consume CEF logs.
32+
- Access to Microsoft Sentinel with [**Microsoft Sentinel Contributor**](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) permissions. For more information, see [Roles and permissions in Microsoft Sentinel](roles.md).
33+
- [Monitoring Contributor](/azure/role-based-access-control/built-in-roles#monitoring-contributor) permissions to create a data collection rule (DCR) and a data collection endpoint (DCE). For more information, see [Data collection rules](https://learn.microsoft.com/azure/azure-monitor/logs/data-collection-rules).
3534
- To create summary rules in the Microsoft Defender portal, you must first onboard your workspace to the Defender portal. For more information, see [Connect Microsoft Sentinel to the Microsoft Defender portal](/microsoft-365/security/defender/microsoft-sentinel-onboard).
3635

3736
## Use summary rules with auxiliary logs (sample process)

0 commit comments

Comments
 (0)