Skip to content

Commit 50b8993

Browse files
authored
Merge pull request #285491 from batamig/cust-intents-mixed
Adding customer intents - mixed files
2 parents 9e2976c + 0d3496b commit 50b8993

File tree

69 files changed

+356
-96
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

69 files changed

+356
-96
lines changed

articles/sentinel/audit-sentinel-data.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,14 @@
11
---
22
title: Audit Microsoft Sentinel queries and activities | Microsoft Docs
33
description: This article describes how to audit queries and activities performed in Microsoft Sentinel.
4-
author: limwainstein
4+
author: batamig
55
ms.topic: how-to
66
ms.date: 01/09/2023
7-
ms.author: lwainstein
7+
ms.author: bagol
8+
9+
10+
#Customer intent: As a security analyst, I want to audit queries and activities in my SOC environment so that I can ensure compliance and monitor security operations effectively.
11+
812
---
913

1014
# Audit Microsoft Sentinel queries and activities

articles/sentinel/audit-table-reference.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,15 @@
11
---
22
title: Microsoft Sentinel audit tables reference
33
description: Learn about the fields in the SentinelAudit tables, used for audit monitoring and analysis.
4-
author: limwainstein
5-
ms.author: lwainstein
4+
author: batamig
5+
ms.author: bagol
66
ms.topic: reference
77
ms.date: 01/17/2023
88
ms.service: microsoft-sentinel
9+
10+
11+
#Customer intent: As a security analyst, I want to understand the schema and usage of Microsoft Sentinel audit tables so that I can effectively monitor user activities within my SIEM environment.
12+
913
---
1014

1115
# Microsoft Sentinel audit tables reference

articles/sentinel/aws-s3-troubleshoot.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,14 @@
11
---
22
title: Troubleshoot AWS S3 connector issues - Microsoft Sentinel
33
description: Troubleshoot AWS S3 connector issues in Microsoft Sentinel.
4-
author: limwainstein
5-
ms.author: lwainstein
4+
author: yelevin
5+
ms.author: yelevin
66
ms.topic: troubleshooting
77
ms.date: 09/08/2022
8-
#Customer intent: As a security operator, I want to quickly identify the cause of the problem occurring with the AWS S3 connector so I can find the steps needed to resolve the problem.
8+
9+
10+
#Customer intent: As a security engineer, I want to troubleshoot AWS S3 connector issues so that I can ensure seamless log ingestion into Microsoft Sentinel.
11+
912
---
1013

1114
# Troubleshoot AWS S3 connector issues
@@ -150,4 +153,4 @@ There might be errors in the health logs, or the health feature might not be ena
150153
151154
In this article, you learned how to quickly identify causes and resolve common issues with the AWS S3 connector.
152155
153-
We welcome feedback, suggestions, requests for features, bug reports or improvements and additions. Go to the [Microsoft Sentinel GitHub repository](https://github.com/Azure/Azure-Sentinel) to create an issue or fork and upload a contribution.
156+
We welcome feedback, suggestions, requests for features, bug reports or improvements and additions. Go to the [Microsoft Sentinel GitHub repository](https://github.com/Azure/Azure-Sentinel) to create an issue or fork and upload a contribution.

articles/sentinel/best-practices-data.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,14 @@
11
---
22
title: Best practices for data collection in Microsoft Sentinel
33
description: Learn about best practices to employ when connecting data sources to Microsoft Sentinel.
4-
author: limwainstein
5-
ms.author: lwainstein
4+
author: yelevin
5+
ms.author: yelevin
66
ms.topic: conceptual
77
ms.date: 01/09/2023
8+
9+
10+
#Customer intent: As a security analyst, I want to implement best practices for Microsoft Sentinel data collection so that I can optimize log ingestion, reduce costs, and enhance security monitoring.
11+
812
---
913

1014
# Data collection best practices

articles/sentinel/cef-name-mapping.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: yelevin
55
ms.author: yelevin
66
ms.topic: reference
77
ms.date: 08/12/2024
8+
9+
10+
#Customer intent: As a security analyst, I want to understand the mapping between CEF fields and CommonSecurityLog fields so that I can accurately interpret and analyze security events in my SIEM system.
11+
812
---
913

1014
# CEF and CommonSecurityLog field mapping

articles/sentinel/configure-content.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,14 @@
11
---
22
title: Configure Microsoft Sentinel content
33
description: In this step of your deployment, you configure the Microsoft Sentinel security content, like your data connectors, analytics rules, automation rules, and more.
4-
author: limwainstein
4+
author: cwatson-cat
55
ms.topic: how-to
66
ms.date: 07/05/2023
7-
ms.author: lwainstein
8-
#Customer intent: As a SOC analyst, I want to configure the Microsoft Sentinel security content, so I can protect my organization against threats.
7+
ms.author: cwatson
8+
9+
10+
#Customer intent: As a security engineer, I want to configure Microsoft Sentinel security content so that analysts can detect, monitor, and respond to security threats effectively.
11+
912
---
1013

1114
# Configure Microsoft Sentinel content
@@ -28,4 +31,4 @@ In the previous deployment step, you enabled Microsoft Sentinel, health monitori
2831
In this article, you learned how to configure the different types of Microsoft Sentinel security content.
2932

3033
> [!div class="nextstepaction"]
31-
>>[Set up multiple workspaces](use-multiple-workspaces.md)
34+
>>[Set up multiple workspaces](use-multiple-workspaces.md)

articles/sentinel/configure-data-retention-archive.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,10 @@ author: cwatson-cat
55
ms.topic: how-to
66
ms.date: 07/21/2024
77
ms.author: cwatson
8-
#Customer intent: As a SOC analyst, I want to set up interactive and long-term data retention settings so I can retain the data that's important to my organization in the long term.
8+
9+
10+
#Customer intent: As a security architect or SOC manager, I want to configure data retention and archiving policies so that I can ensure long-term storage of important data at a reduced cost.
11+
912
---
1013

1114
# Configure interactive and long-term data retention in Microsoft Sentinel

articles/sentinel/connect-azure-virtual-desktop.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,14 @@
11
---
22
title: Connect Azure Virtual Desktop to Microsoft Sentinel | Microsoft Docs
33
description: Learn to connect your Azure Virtual Desktop data to Microsoft Sentinel.
4-
author: limwainstein
4+
author: yelevin
55
ms.topic: how-to
66
ms.date: 01/09/2023
7-
ms.author: lwainstein
7+
ms.author: yelevin
8+
9+
10+
#Customer intent: As a security analyst, I want to monitor Azure Virtual Desktop environments using Microsoft Sentinel so that I can enhance remote work capabilities while maintaining security.
11+
812
---
913

1014
# Connect Azure Virtual Desktop data to Microsoft Sentinel

articles/sentinel/connect-dns-ama.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,15 @@
11
---
22
title: Stream and filter Windows DNS logs with the AMA connector
33
description: Use the AMA connector to upload and filter data from your Windows DNS server logs. You can then dive into your logs to protect your DNS servers from threats and attacks.
4-
author: limwainstein
4+
author: yelevin
55
ms.topic: how-to
66
ms.date: 01/05/2022
7-
ms.author: lwainstein
7+
ms.author: yelevin
88
#Customer intent: As a security operator, I want to proactively monitor Windows DNS activities so that I can prevent threats and attacks on DNS servers.
9+
10+
11+
#Customer intent: As a security engineer, I want to stream and filter DNS server logs using a cloud-based monitoring agent so that analysts can detect and mitigate potential threats efficiently.
12+
913
---
1014

1115
# Stream and filter data from Windows DNS servers with the AMA connector

articles/sentinel/create-custom-connector.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,8 @@ author: austinmccollum
55
ms.topic: conceptual
66
ms.date: 10/01/2024
77
ms.author: austinmc
8+
#Customer intent: As a security engineer, I want to know which Microsoft Sentinel custom data connector would be most appropriate to build for ingesting data from sources with no out-of-the-box solution.
9+
810
---
911

1012
# Resources for creating Microsoft Sentinel custom connectors

0 commit comments

Comments
 (0)