|
1 | 1 | ---
|
2 |
| -title: Detect threats by using hunting livestream in Microsoft Sentinel |
3 |
| -description: Learn how to use hunting livestream in Microsoft Sentinel to actively monitor a compromise event. |
| 2 | +title: Detect threats by using hunting livestream in Microsoft Sentinel |
| 3 | +description: Detect threats in real time with hunting livestream in Microsoft Sentinel. Set up sessions, receive notifications, and take action fast. |
4 | 4 | ms.topic: how-to
|
5 |
| -ms.date: 04/24/2024 |
| 5 | +ms.date: 07/06/2025 |
6 | 6 | ms.author: monaberdugo
|
7 | 7 | author: mberdugo
|
8 | 8 | ms.collection: usx-security
|
9 | 9 | appliesto:
|
10 |
| - - Microsoft Sentinel in the Microsoft Defender portal |
11 |
| - - Microsoft Sentinel in the Azure portal |
12 |
| - |
13 |
| - |
14 |
| -#Customer intent: As a security analyst, I want to create and manage hunting livestream sessions so that I can detect and respond to threats in real-time. |
15 |
| - |
| 10 | + - Microsoft Sentinel in the Microsoft Defender portal |
| 11 | + - Microsoft Sentinel in the Azure portal |
| 12 | +ms.custom: |
| 13 | + - ai-gen-docs-bap |
| 14 | + - ai-gen-description |
| 15 | + - ai-seo-date:07/06/2025 |
16 | 16 | ---
|
17 | 17 |
|
18 | 18 | # Detect threats by using hunting livestream in Microsoft Sentinel
|
19 | 19 |
|
20 |
| -Use hunting livestream to create interactive sessions that let you test newly created queries as events occur, get notifications from the sessions when a match is found, and launch investigations if necessary. You can quickly create a livestream session using any Log Analytics query. |
| 20 | +Use hunting livestream to create interactive sessions that let you test newly created queries as events occur, get notifications from the sessions when a match is found, and launch investigations if necessary. You can quickly create a livestream session using any Log Analytics query. This article is about hunting in Microsoft Sentinel which also exists in Defender. For advanced hunting in Microsoft Defender, see [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview). |
21 | 21 |
|
22 | 22 | [!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
|
23 | 23 |
|
24 | 24 | ## Create a livestream session
|
25 | 25 |
|
26 | 26 | You can create a livestream session from an existing hunting query, or create your session from scratch.
|
27 | 27 |
|
28 |
| -1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Threat management**, select **Hunting**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Threat management** > **Hunting**. |
| 28 | +1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Threat management**, select **Hunting**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Threat management** > **Hunting**. Make sure you select *Hunting*, and not *Advanced hunting*. |
29 | 29 |
|
30 | 30 | 1. To create a livestream session from a hunting query:
|
31 | 31 |
|
|
0 commit comments