|
5 | 5 | items:
|
6 | 6 | - name: What is Microsoft Sentinel?
|
7 | 7 | href: overview.md
|
| 8 | + - name: Microsoft Sentinel data lake overview |
| 9 | + href: datalake/sentinel-lake-overview.md |
| 10 | + displayName: data lake |
8 | 11 | - name: What's new
|
9 | 12 | href: whats-new.md
|
10 | 13 | - name: Best practices
|
11 | 14 | href: best-practices.md
|
12 | 15 | - name: Experience in Defender portal
|
13 | 16 | href: microsoft-sentinel-defender-portal.md
|
| 17 | +- name: Data lake exploration |
| 18 | + items: |
| 19 | + - name: KQL for data lake exploration |
| 20 | + items: |
| 21 | + - name: Overview |
| 22 | + href: datalake/kql-overview.md |
| 23 | + displayName: data lake |
| 24 | + - name: Run KQL queries |
| 25 | + href: datalake/kql-queries.md |
| 26 | + displayName: data lake |
| 27 | + - name: Create KQL jobs |
| 28 | + href: datalake/kql-jobs.md |
| 29 | + displayName: data lake |
| 30 | + - name: Manage KQL jobs |
| 31 | + href: datalake/kql-manage-jobs.md |
| 32 | + displayName: data lake |
| 33 | + - name: Troubleshoot KQL for the lake |
| 34 | + href: datalake/kql-troubleshoot.md |
| 35 | + displayName: data lake |
| 36 | + - name: Notebooks for data lake exploration |
| 37 | + items: |
| 38 | + - name: Overview |
| 39 | + href: datalake/notebooks-overview.md |
| 40 | + displayName: data lake |
| 41 | + - name: Run notebooks |
| 42 | + href: datalake/notebooks.md |
| 43 | + displayName: data lake |
| 44 | + - name: Microsoft Sentinel provider class reference |
| 45 | + href: datalake/sentinel-provider-class-reference.md |
| 46 | + displayName: data lake |
| 47 | + - name: Create and manage notebook jobs |
| 48 | + href: datalake/notebook-jobs.md |
| 49 | + displayName: data lake |
| 50 | + - name: Notebook examples for data lake exploration |
| 51 | + href: datalake/notebook-examples.md |
14 | 52 | - name: Plan
|
15 | 53 | items:
|
16 | 54 | - name: Deployment planning guide
|
17 | 55 | href: deploy-overview.md
|
18 | 56 | - name: Prerequisites
|
19 | 57 | href: prerequisites.md
|
20 | 58 | - name: Workspace architecture
|
21 |
| - items: |
22 |
| - - name: Design workspace architecture |
23 |
| - href: /azure/azure-monitor/logs/workspace-design?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
| 59 | + items: |
24 | 60 | - name: Review sample workspace designs
|
25 | 61 | href: sample-workspace-designs.md
|
26 | 62 | - name: Prepare for multiple workspaces
|
|
29 | 65 | href: prioritize-data-connectors.md
|
30 | 66 | - name: Plan roles and permissions
|
31 | 67 | href: roles.md
|
| 68 | + displayName: data lake |
32 | 69 | - name: Plan interactive and long-term data retention
|
33 | 70 | href: log-plans.md
|
34 | 71 | - name: Plan costs
|
|
55 | 92 | href: quickstart-onboard.md
|
56 | 93 | - name: Connect Microsoft Sentinel to the Defender portal
|
57 | 94 | href: /unified-secops-platform/microsoft-sentinel-onboard?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
|
| 95 | + - name: Onboard to Microsoft Sentinel data lake |
| 96 | + href: datalake/sentinel-lake-onboarding.md |
| 97 | + displayName: data lake |
| 98 | + - name: Set up connectors for the Microsoft Sentinel data lake |
| 99 | + href: datalake/sentinel-lake-connectors.md |
| 100 | + displayName: data lake |
58 | 101 | - name: Configure content
|
59 | 102 | href: configure-content.md
|
60 | 103 | - name: Set up multiple workspaces
|
|
356 | 399 | href: summary-rules.md
|
357 | 400 | - name: Aggregate insights from raw data into an Auxiliary table
|
358 | 401 | href: summary-rules-tutorial.md
|
| 402 | +- name: Manage data |
| 403 | + items: |
| 404 | + - name: Data management overview |
| 405 | + href: manage-data-overview.md |
| 406 | + displayName: table management, tiers, retention, manage data, tables |
| 407 | + - name: Manage tables, tiers, and retention |
| 408 | + href: manage-table-tiers-retention.md |
| 409 | + displayName: table management, tiers, retention, tables |
359 | 410 | - name: Integrate threat intelligence
|
360 | 411 | items:
|
361 | 412 | - name: Overview
|
|
665 | 716 | href: soc-optimization/soc-optimization-reference.md
|
666 | 717 | - name: Manage Microsoft Sentinel
|
667 | 718 | items:
|
| 719 | + |
668 | 720 | - name: Manage costs and billing
|
669 | 721 | items:
|
670 | 722 | - name: Monitor costs
|
|
675 | 727 | href: enroll-simplified-pricing-tier.md
|
676 | 728 | - name: Optimize costs with pre-purchase plan
|
677 | 729 | href: billing-pre-purchase-plan.md
|
678 |
| - - name: Manage data retention |
679 |
| - href: /azure/azure-monitor/logs/data-retention-configure?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
680 |
| - - name: Auxiliary logs use cases |
| 730 | + - name: Data lake use cases |
681 | 731 | href: basic-logs-use-cases.md
|
682 | 732 | - name: Manage multiple workspaces
|
683 | 733 | items:
|
|
695 | 745 | href: multiple-workspace-view.md
|
696 | 746 | - name: Manage your intellectual property in Microsoft Sentinel
|
697 | 747 | href: mssp-protect-intellectual-property.md
|
698 |
| - - name: Manage workspace access |
| 748 | + - name: Manage workspace access with resource-context RBAC |
699 | 749 | href: resource-context-rbac.md
|
700 | 750 | - name: Set up customer-managed keys
|
701 | 751 | href: customer-managed-keys.md
|
|
717 | 767 | href: monitor-analytics-rule-integrity.md
|
718 | 768 | - name: Auditing Microsoft Sentinel with Azure Activity Logs
|
719 | 769 | href: audit-sentinel-data.md
|
| 770 | + - name: Audit log for Microsoft Sentinel data lake |
| 771 | + href: datalake/auditing-lake-activities.md |
| 772 | + displayName: data lake |
720 | 773 | - name: Remove Microsoft Sentinel from your workspaces
|
721 | 774 | href: offboard.md
|
722 | 775 | - name: Build and publish Microsoft Sentinel solutions
|
|
757 | 810 | href: aws-s3-troubleshoot.md
|
758 | 811 | - name: Reference
|
759 | 812 | items:
|
760 |
| - - name: Service limits |
| 813 | + - name: Microsoft Sentinel service limits |
761 | 814 | href: sentinel-service-limits.md
|
| 815 | + - name: Microsoft Sentinel data lake service limits |
| 816 | + href: datalake/sentinel-lake-service-limits.md |
| 817 | + displayName: data lake |
762 | 818 | - name: Microsoft Sentinel REST-API
|
763 | 819 | href: /rest/api/securityinsights/
|
764 | 820 | - name: OOTB content centralization changes
|
|
0 commit comments