You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/automation/create-playbooks.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,8 +6,8 @@ ms.author: bagol
6
6
ms.topic: how-to
7
7
ms.date: 10/16/2024
8
8
appliesto:
9
-
- Microsoft Sentinel in the Azure portal
10
9
- Microsoft Sentinel in the Microsoft Defender portal
10
+
- Microsoft Sentinel in the Azure portal
11
11
ms.collection: usx-security
12
12
#Customer intent: As a security analyst, I want to manage automated response playbooks so that I can efficiently handle incidents and alerts in my environment.
13
13
@@ -50,14 +50,14 @@ This article describes how to create and manage Microsoft Sentinel playbooks. Yo
50
50
51
51
Follow these steps to create a new playbook in Microsoft Sentinel:
52
52
53
-
1. In the [Azure portal](https://portal.azure.com) or in the [Defender portal](https://security.microsoft.com/), go to your Microsoft Sentinel workspace. On the workspace menu, under **Configuration**, select **Automation**.
53
+
1. In the [Defender portal](https://security.microsoft.com/) or in the [Azure portal](https://portal.azure.com), go to your Microsoft Sentinel workspace. On the workspace menu, under **Configuration**, select **Automation**.
54
+
55
+
#### [Defender portal](#tab/defender-portal)
56
+
:::image type="content" source="../media/create-playbooks/add-new-playbook-defender.png" alt-text="Screenshot shows Defender portal and Microsoft Sentinel Automation page with Create selected." lightbox="../media/create-playbooks/add-new-playbook-defender.png":::
54
57
55
58
#### [Azure portal](#tab/azure-portal)
56
59
:::image type="content" source="../media/create-playbooks/add-new-playbook.png" alt-text="Screenshot shows Azure portal and Microsoft Sentinel Automation page with Create selected." lightbox="../media/create-playbooks/add-new-playbook.png":::
57
60
58
-
#### [Defender portal](#tab/defender-portal)
59
-
:::image type="content" source="../media/create-playbooks/add-new-playbook-defender.png" alt-text="Screenshot shows Defender portal and Microsoft Sentinel Automation page with Create selected." lightbox="../media/create-playbooks/add-new-playbook-defender.png":::
60
-
61
61
---
62
62
63
63
1. From the top menu, select **Create**, and then select one of the following options:
Copy file name to clipboardExpand all lines: articles/sentinel/configure-data-connector.md
+9-13Lines changed: 9 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,8 +6,8 @@ ms.topic: how-to
6
6
ms.date: 03/28/2024
7
7
ms.author: cwatson
8
8
appliesto:
9
-
- Microsoft Sentinel in the Azure portal
10
9
- Microsoft Sentinel in the Microsoft Defender portal
10
+
- Microsoft Sentinel in the Azure portal
11
11
ms.collection: usx-security
12
12
13
13
@@ -42,14 +42,10 @@ After you or someone in your organization installs the solution that includes th
42
42
1. Search for and select the connector. If you don't see the data connector you want, install the solution associated with it from the **Content Hub**.
43
43
1. Select **Open connector page**.
44
44
45
-
#### [Azure portal](#tab/azure-portal)
46
-
47
-
:::image type="content" source="media/configure-data-connector/open-connector-page-option.png" alt-text="Screenshot of data connector details page with open connector page button.":::
48
-
49
45
#### [Defender portal](#tab/defender-portal)
50
-
51
46
:::image type="content" source="media/configure-data-connector/open-connector-page-option-defender-portal.png" alt-text="Screenshot of data connector details page in the Defender portal.":::
52
-
47
+
#### [Azure portal](#tab/azure-portal)
48
+
:::image type="content" source="media/configure-data-connector/open-connector-page-option.png" alt-text="Screenshot of data connector details page with open connector page button.":::
53
49
---
54
50
55
51
1. Review the **Prerequisites**. To configure the data connector, fulfill all the prerequisites.
@@ -69,15 +65,15 @@ After you enable the connector successfully, the connector begins to stream data
69
65
70
66
To view the data:
71
67
72
-
#### [Azure portal](#tab/azure-portal-1)
68
+
#### [Defender portal](#tab/defender-portal-1)
73
69
74
-
Query the tables in the Microsoft Sentinel workspace linked to your Microsoft Sentinel workspace.
70
+
See [Where to find your Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender#where-to-find-your-microsoft-sentinel-data).
75
71
76
-
#### [Defender portal](#tab/defender-portal-1)
77
-
78
-
See [Where to find your Microsoft Sentinel data in Microsoft Defender portal](/defender-xdr/advanced-hunting-microsoft-defender#where-to-find-your-microsoft-sentinel-data).
72
+
#### [Azure portal](#tab/azure-portal-1)
79
73
80
-
---
74
+
Query the tables in the Microsoft Sentinel workspace linked to your Microsoft Sentinel workspace.
Copy file name to clipboardExpand all lines: articles/sentinel/connect-data-sources.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,8 +6,8 @@ ms.topic: conceptual
6
6
ms.date: 11/06/2024
7
7
ms.author: yelevin
8
8
appliesto:
9
-
- Microsoft Sentinel in the Azure portal
10
9
- Microsoft Sentinel in the Microsoft Defender portal
10
+
- Microsoft Sentinel in the Azure portal
11
11
ms.collection: usx-security
12
12
#Customer intent: As a security engineer, I want to use data connectors to integrate various data sources into Microsoft Sentinel so that I can enhance threat detection and response capabilities.
13
13
---
@@ -32,14 +32,14 @@ Microsoft Sentinel solutions provide packaged security content, including data c
32
32
33
33
The Microsoft Sentinel **Data connectors** page lists the installed or in-use data connectors.
34
34
35
-
#### [Azure portal](#tab/azure-portal)
36
-
37
-
:::image type="content" source="media/connect-data-sources/data-connector-list.png" alt-text="Screenshot of the data connectors gallery." lightbox="media/connect-data-sources/data-connector-list.png":::
38
-
39
35
#### [Defender portal](#tab/defender-portal)
40
36
41
37
:::image type="content" source="media/connect-data-sources/data-connector-list-defender.png" alt-text="Screenshot of the data connectors gallery." lightbox="media/connect-data-sources/data-connector-list-defender.png":::
42
38
39
+
#### [Azure portal](#tab/azure-portal)
40
+
41
+
:::image type="content" source="media/connect-data-sources/data-connector-list.png" alt-text="Screenshot of the data connectors gallery." lightbox="media/connect-data-sources/data-connector-list.png":::
42
+
43
43
---
44
44
45
45
To add more data connectors, install the solution associated with the data connector from the **Content Hub**. For more information, see the following articles:
Copy file name to clipboardExpand all lines: articles/sentinel/create-analytics-rule-from-template.md
+11-11Lines changed: 11 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,8 +6,8 @@ ms.author: yelevin
6
6
ms.topic: how-to
7
7
ms.date: 07/02/2024
8
8
appliesto:
9
-
- Microsoft Sentinel in the Azure portal
10
9
- Microsoft Sentinel in the Microsoft Defender portal
10
+
- Microsoft Sentinel in the Azure portal
11
11
ms.collection: usx-security
12
12
13
13
@@ -28,9 +28,9 @@ This article shows you how to create a scheduled analytics rule using a template
28
28
29
29
To view the installed analytics rules in Microsoft Sentinel, go to the **Analytics** page. The **Rule templates** tab displays all the installed rule templates. To find more rule templates, go to the **Content hub** in Microsoft Sentinel to install the related product solutions or standalone content.
30
30
31
-
# [Azure portal](#tab/azure-portal)
31
+
# [Defender portal](#tab/defender-portal)
32
32
33
-
1. From the **Configuration** section of the Microsoft Sentinel navigation menu, select**Analytics**.
33
+
1. From the Microsoft Defender navigation menu, expand **Microsoft Sentinel**, then **Configuration**. Select**Analytics**.
34
34
35
35
1. On the **Analytics** screen, select the **Rule templates** tab.
36
36
@@ -40,11 +40,11 @@ To view the installed analytics rules in Microsoft Sentinel, go to the **Analyti
40
40
41
41
1. From the resulting list, select **Scheduled**. Then select **Apply**.
42
42
43
-
:::image type="content" source="media/create-analytics-rule-from-template/view-detections.png" alt-text="Screenshot of scheduled analytics rule templates in Microsoft Azure portal." lightbox="media/create-analytics-rule-from-template/view-detections.png":::
43
+
:::image type="content" source="media/create-analytics-rule-from-template/view-detections-defender.png" alt-text="Screenshot of scheduled analytics rule templates in Microsoft Defender portal." lightbox="media/create-analytics-rule-from-template/view-detections-defender.png":::
44
44
45
-
# [Defender portal](#tab/defender-portal)
45
+
# [Azure portal](#tab/azure-portal)
46
46
47
-
1. From the Microsoft Defender navigation menu, expand **Microsoft Sentinel**, then **Configuration**. Select**Analytics**.
47
+
1. From the **Configuration** section of the Microsoft Sentinel navigation menu, select**Analytics**.
48
48
49
49
1. On the **Analytics** screen, select the **Rule templates** tab.
50
50
@@ -54,22 +54,22 @@ To view the installed analytics rules in Microsoft Sentinel, go to the **Analyti
54
54
55
55
1. From the resulting list, select **Scheduled**. Then select **Apply**.
56
56
57
-
:::image type="content" source="media/create-analytics-rule-from-template/view-detections-defender.png" alt-text="Screenshot of scheduled analytics rule templates in Microsoft Defender portal." lightbox="media/create-analytics-rule-from-template/view-detections-defender.png":::
57
+
:::image type="content" source="media/create-analytics-rule-from-template/view-detections.png" alt-text="Screenshot of scheduled analytics rule templates in Microsoft Azure portal." lightbox="media/create-analytics-rule-from-template/view-detections.png":::
58
58
59
59
---
60
60
61
61
## Create a rule from a template
62
62
63
63
This procedure describes how to create an analytics rule from a template.
64
64
65
-
# [Azure portal](#tab/azure-portal)
66
-
67
-
From the **Configuration** section of the Microsoft Sentinel navigation menu, select **Analytics**.
68
-
69
65
# [Defender portal](#tab/defender-portal)
70
66
71
67
From the Microsoft Defender navigation menu, expand **Microsoft Sentinel**, then **Configuration**. Select **Analytics**.
72
68
69
+
# [Azure portal](#tab/azure-portal)
70
+
71
+
From the **Configuration** section of the Microsoft Sentinel navigation menu, select **Analytics**.
72
+
73
73
---
74
74
75
75
1. On the **Analytics** screen, select the **Rule templates** tab.
Copy file name to clipboardExpand all lines: articles/sentinel/create-analytics-rules.md
+34-34Lines changed: 34 additions & 34 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,8 +6,8 @@ ms.author: yelevin
6
6
ms.topic: how-to
7
7
ms.date: 10/16/2024
8
8
appliesto:
9
-
- Microsoft Sentinel in the Azure portal
10
9
- Microsoft Sentinel in the Microsoft Defender portal
10
+
- Microsoft Sentinel in the Azure portal
11
11
ms.collection: usx-security
12
12
13
13
@@ -58,18 +58,18 @@ This section describes how to create a rule using the Azure or Defender portals.
58
58
59
59
To get started, go to the **Analytics** page in Microsoft Sentinel to create a scheduled analytics rule.
60
60
61
-
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under**Configuration**, select**Analytics**.<br>For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com), select**Microsoft Sentinel** > **Configuration** >**Analytics**.
61
+
1. For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com), select**Microsoft Sentinel** > **Configuration** >**Analytics**.For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under**Configuration**, select**Analytics**.
62
62
63
63
1. Select **+Create** and select **Scheduled query rule**.
64
64
65
-
# [Azure portal](#tab/azure-portal)
66
-
67
-
:::image type="content" source="media/create-analytics-rules/create-scheduled-query.png" alt-text="Screenshot of Analytics screen in Azure portal." lightbox="media/create-analytics-rules/create-scheduled-query.png":::
68
-
69
65
# [Defender portal](#tab/defender-portal)
70
66
71
67
:::image type="content" source="media/create-analytics-rules/defender-create-scheduled-query.png" alt-text="Screenshot of Analytics screen in Defender portal." lightbox="media/create-analytics-rules/defender-create-scheduled-query.png":::
72
68
69
+
# [Azure portal](#tab/azure-portal)
70
+
71
+
:::image type="content" source="media/create-analytics-rules/create-scheduled-query.png" alt-text="Screenshot of Analytics screen in Azure portal." lightbox="media/create-analytics-rules/create-scheduled-query.png":::
72
+
73
73
---
74
74
75
75
### Name the rule and define general information
@@ -88,14 +88,14 @@ In the Azure portal, stages are represented visually as tabs. In the Defender po
88
88
89
89
1. Select **Next: Set rule logic**.
90
90
91
-
# [Azure portal](#tab/azure-portal)
92
-
93
-
:::image type="content" source="media/create-analytics-rules/general-tab.png" alt-text="Screenshot of opening screen of analytics rule wizard in the Azure portal.":::
94
-
95
91
# [Defender portal](#tab/defender-portal)
96
92
97
93
:::image type="content" source="media/create-analytics-rules/defender-wizard-general.png" alt-text="Screenshot of opening screen of analytics rule wizard in the Defender portal.":::
98
94
95
+
# [Azure portal](#tab/azure-portal)
96
+
97
+
:::image type="content" source="media/create-analytics-rules/general-tab.png" alt-text="Screenshot of opening screen of analytics rule wizard in the Azure portal.":::
98
+
99
99
---
100
100
101
101
### Define the rule logic
@@ -150,18 +150,18 @@ The next step is to set the rule logic which includes adding the Kusto query tha
150
150
151
151
1. Select **Next: Incident settings**.
152
152
153
-
# [Azure portal](#tab/azure-portal)
154
-
155
-
:::image type="content" source="media/create-analytics-rules/set-rule-logic-1.png" alt-text="Screenshot of first half of set rule logic tab in the analytics rule wizard in the Azure portal.":::
156
-
157
-
:::image type="content" source="media/create-analytics-rules/set-rule-logic-2.png" alt-text="Screenshot of second half of set rule logic tab in the analytics rule wizard in the Azure portal.":::
158
-
159
153
# [Defender portal](#tab/defender-portal)
160
154
161
155
:::image type="content" source="media/create-analytics-rules/defender-set-rule-logic-1.png" alt-text="Screenshot of first half of set rule logic tab in the analytics rule wizard in the Defender portal.":::
162
156
163
157
:::image type="content" source="media/create-analytics-rules/defender-set-rule-logic-2.png" alt-text="Screenshot of second half of set rule logic tab in the analytics rule wizard in the Defender portal.":::
164
158
159
+
# [Azure portal](#tab/azure-portal)
160
+
161
+
:::image type="content" source="media/create-analytics-rules/set-rule-logic-1.png" alt-text="Screenshot of first half of set rule logic tab in the analytics rule wizard in the Azure portal.":::
162
+
163
+
:::image type="content" source="media/create-analytics-rules/set-rule-logic-2.png" alt-text="Screenshot of second half of set rule logic tab in the analytics rule wizard in the Azure portal.":::
164
+
165
165
---
166
166
167
167
### Configure the incident creation settings
@@ -217,14 +217,14 @@ In the **Incident settings** tab, choose whether Microsoft Sentinel turns alerts
217
217
218
218
1. Select **Next: Automated response**.
219
219
220
-
# [Azure portal](#tab/azure-portal)
221
-
222
-
:::image type="content" source="media/create-analytics-rules/incident-settings-tab.png" alt-text="Screenshot of incident settings screen of analytics rule wizard in the Azure portal.":::
223
-
224
220
# [Defender portal](#tab/defender-portal)
225
221
226
222
:::image type="content" source="media/create-analytics-rules/defender-incident-settings.png" alt-text="Screenshot of incident settings screen of analytics rule wizard in the Defender portal.":::
227
223
224
+
# [Azure portal](#tab/azure-portal)
225
+
226
+
:::image type="content" source="media/create-analytics-rules/incident-settings-tab.png" alt-text="Screenshot of incident settings screen of analytics rule wizard in the Azure portal.":::
227
+
228
228
---
229
229
230
230
### Review or add automated responses
@@ -241,14 +241,14 @@ In the **Incident settings** tab, choose whether Microsoft Sentinel turns alerts
241
241
242
242
- If you still have any playbooks listed here, you should instead create an automation rule based on the **alert created trigger** and invoke the playbook from the automation rule. After you've done that, select the ellipsis at the end of the line of the playbook listed here, and select **Remove**. See [Migrate your Microsoft Sentinel alert-trigger playbooks to automation rules](migrate-playbooks-to-automation-rules.md) for full instructions.
243
243
244
-
# [Azure portal](#tab/azure-portal)
245
-
246
-
:::image type="content" source="media/create-analytics-rules/automated-response-tab.png" alt-text="Screenshot of automated response screen of analytics rule wizard in the Azure portal.":::
247
-
248
244
# [Defender portal](#tab/defender-portal)
249
245
250
246
:::image type="content" source="media/create-analytics-rules/defender-automated-response.png" alt-text="Screenshot of automated response screen of analytics rule wizard in the Defender portal.":::
251
247
248
+
# [Azure portal](#tab/azure-portal)
249
+
250
+
:::image type="content" source="media/create-analytics-rules/automated-response-tab.png" alt-text="Screenshot of automated response screen of analytics rule wizard in the Azure portal.":::
251
+
252
252
---
253
253
254
254
1. Select **Next: Review and create** to review all the settings for your new analytics rule.
@@ -261,14 +261,14 @@ In the **Incident settings** tab, choose whether Microsoft Sentinel turns alerts
261
261
262
262
1. Correct the error and go back to the **Review and create** tab to run the validation again.
263
263
264
-
# [Azure portal](#tab/azure-portal)
265
-
266
-
:::image type="content" source="media/create-analytics-rules/review-and-create-tab.png" alt-text="Screenshot of validation screen of analytics rule wizard in the Azure portal.":::
267
-
268
264
# [Defender portal](#tab/defender-portal)
269
265
270
266
:::image type="content" source="media/create-analytics-rules/defender-review-and-create.png" alt-text="Screenshot of validation screen of analytics rule wizard in the Defender portal.":::
271
267
268
+
# [Azure portal](#tab/azure-portal)
269
+
270
+
:::image type="content" source="media/create-analytics-rules/review-and-create-tab.png" alt-text="Screenshot of validation screen of analytics rule wizard in the Azure portal.":::
271
+
272
272
---
273
273
274
274
## View the rule and its output
@@ -279,18 +279,18 @@ You can find your newly created custom rule (of type "Scheduled") in the table u
279
279
280
280
### View the results of the rule
281
281
282
-
# [Azure portal](#tab/azure-portal)
283
-
284
-
To view the results of the analytics rules you create in the Azure portal, go to the **Incidents** page, where you can triage incidents, [investigate them](investigate-cases.md), and [remediate the threats](respond-threats-during-investigation.md).
285
-
286
-
:::image type="content" source="media/create-analytics-rules/view-incidents.png" alt-text="Screenshot of incidents page in the Azure portal." lightbox="media/create-analytics-rules/view-incidents.png":::
287
-
288
282
# [Defender portal](#tab/defender-portal)
289
283
290
284
To view the results of the analytics rules you create in the Defender portal, expand **Investigation & response** in the navigation menu, then **Incidents & alerts**. View incidents on the **Incidents** page, where you can triage incidents, [investigate them](investigate-cases.md), and [remediate the threats](respond-threats-during-investigation.md). View individual alerts on the **Alerts** page.
291
285
292
286
:::image type="content" source="media/create-analytics-rules/defender-view-incidents.png" alt-text="Screenshot of incidents page in the Azure portal." lightbox="media/create-analytics-rules/defender-view-incidents.png":::
293
287
288
+
# [Azure portal](#tab/azure-portal)
289
+
290
+
To view the results of the analytics rules you create in the Azure portal, go to the **Incidents** page, where you can triage incidents, [investigate them](investigate-cases.md), and [remediate the threats](respond-threats-during-investigation.md).
291
+
292
+
:::image type="content" source="media/create-analytics-rules/view-incidents.png" alt-text="Screenshot of incidents page in the Azure portal." lightbox="media/create-analytics-rules/view-incidents.png":::
0 commit comments