You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/data-connectors/netskope-data-connector.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -271,4 +271,4 @@ Using the ARM template deploy the function apps for ingestion of Netskope events
271
271
272
272
## Next steps
273
273
274
-
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/netskope.netskope_mss?tab=Overview) in the Azure Marketplace.
274
+
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/netskope.netskope-for-azure?tab=Overview) in the Azure Marketplace.
Copy file name to clipboardExpand all lines: articles/sentinel/data-connectors/netskope-web-transactions-data-connector.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -153,4 +153,4 @@ Use the following step-by-step instructions to deploy the docker based data conn
153
153
154
154
## Next steps
155
155
156
-
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/netskope.netskope_mss?tab=Overview) in the Azure Marketplace.
156
+
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/netskope.netskope-for-azure?tab=Overview) in the Azure Marketplace.
Copy file name to clipboardExpand all lines: articles/sentinel/data-connectors/netskope.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -148,4 +148,4 @@ This method provides the step-by-step instructions to deploy the Netskope connec
148
148
149
149
## Next steps
150
150
151
-
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/netskope.netskope_mss?tab=Overview) in the Azure Marketplace.
151
+
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/netskope.netskope-for-azure?tab=Overview) in the Azure Marketplace.
Copy file name to clipboardExpand all lines: articles/sentinel/data-connectors/qualys-vm-knowledgebase.md
+9-11Lines changed: 9 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,13 +58,10 @@ To integrate with Qualys VM KnowledgeBase (using Azure Functions) make sure you
58
58
## Vendor installation instructions
59
59
60
60
61
-
**NOTE:** This data connector depends on a parser based on a Kusto Function to work as expected which is deployed as part of the solution. To view the function code in Log Analytics, open Log Analytics/Microsoft Sentinel Logs blade, click Functions and search for the alias QualysVM Knowledgebase and load the function code or click [here](https://aka.ms/sentinel-crowdstrikefalconendpointprotection-parser), on the second line of the query, enter the hostname(s) of your QualysVM Knowledgebase device(s) and any other unique identifiers for the logstream. The function usually takes 10-15 minutes to activate after solution installation/update.
62
-
63
-
64
-
>This data connector depends on a parser based on a Kusto Function to work as expected. [Follow the steps](https://aka.ms/sentinel-qualyskb-parser) to use the Kusto function alias, **QualysKB**
65
-
66
-
67
-
>**(Optional Step)** Securely store workspace and API authorization key(s) or token(s) in Azure Key Vault. Azure Key Vault provides a secure mechanism to store and retrieve key values. [Follow these instructions](/azure/app-service/app-service-key-vault-references) to use Azure Key Vault with an Azure Function App.
61
+
> [!NOTE]
62
+
> This data connector depends on a parser based on a Kusto Function to work as expected which is deployed as part of the solution. To view the function code in Log Analytics, open Log Analytics/Microsoft Sentinel Logs blade, click Functions and search for the alias QualysVM Knowledgebase and load the function code, on the second line of the query, enter the hostname(s) of your QualysVM Knowledgebase device(s) and any other unique identifiers for the logstream. The function usually takes 10-15 minutes to activate after solution installation/update.
63
+
> This data connector depends on a parser based on a Kusto Function to work as expected. [Follow the steps](https://aka.ms/sentinel-qualyskb-parser) to use the Kusto function alias, **QualysKB**
64
+
> **(Optional Step)** Securely store workspace and API authorization key(s) or token(s) in Azure Key Vault. Azure Key Vault provides a secure mechanism to store and retrieve key values. [Follow these instructions](/azure/app-service/app-service-key-vault-references) to use Azure Key Vault with an Azure Function App.
68
65
69
66
70
67
**STEP 1 - Configuration steps for the Qualys API**
@@ -73,14 +70,15 @@ To integrate with Qualys VM KnowledgeBase (using Azure Functions) make sure you
73
70
2. Click on the **New** drop-down menu and select **Users**.
74
71
3. Create a username and password for the API account.
75
72
4. In the **User Roles** tab, ensure the account role is set to **Manager** and access is allowed to **GUI** and **API**
76
-
4. Log out of the administrator account and log into the console with the new API credentials for validation, then log out of the API account.
77
-
5. Log back into the console using an administrator account and modify the API accounts User Roles, removing access to **GUI**.
78
-
6. Save all changes.
73
+
5. Log out of the administrator account and log into the console with the new API credentials for validation, then log out of the API account.
74
+
6. Log back into the console using an administrator account and modify the API accounts User Roles, removing access to **GUI**.
75
+
7. Save all changes.
79
76
80
77
81
78
**STEP 2 - Choose ONE from the following two deployment options to deploy the connector and the associated Azure Function**
82
79
83
-
>**IMPORTANT:** Before deploying the Qualys KB connector, have the Workspace ID and Workspace Primary Key (can be copied from the following), as well as the Qualys API username and password, readily available.
80
+
> [!IMPORTANT]
81
+
> Before deploying the Qualys KB connector, have the Workspace ID and Workspace Primary Key (can be copied from the following), as well as the Qualys API username and password, readily available.
Copy file name to clipboardExpand all lines: articles/sentinel/data-connectors/senservapro.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -220,7 +220,7 @@ let timeframe = 14d;
220
220
221
221
1. Setup the data connection
222
222
223
-
Visit [Senserva Setup](https://blog.senserva.com/senserva-and-microsoft-sentinel-overview/) for information on setting up the Senserva data connection, support, or any other questions. The Senserva installation will configure a Log Analytics Workspace for output. Deploy Microsoft Sentinel onto the configured Log Analytics Workspace to finish the data connection setup by following [this onboarding guide.](/azure/sentinel/quickstart-onboard)
223
+
Visit [Senserva Setup](https://www.microsoft.com/en-us/americas-partner-blog/2024/07/30/bulletproof-partners-with-senserva-to-innovate-security-solutions-for-microsoft-customers/) for information on setting up the Senserva data connection, support, or any other questions. The Senserva installation will configure a Log Analytics Workspace for output. Deploy Microsoft Sentinel onto the configured Log Analytics Workspace to finish the data connection setup by following [this onboarding guide.](/azure/sentinel/quickstart-onboard)
# Sophos Cloud Optix connector for Microsoft Sentinel
13
13
14
-
The [Sophos Cloud Optix](https://www.sophos.com/products/cloud-optix.aspx) connector allows you to easily connect your Sophos Cloud Optix logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's cloud security and compliance posture and improves your cloud security operation capabilities.
14
+
The [Sophos Cloud Optix](https://www.sophos.com/products/cloud-optix) connector allows you to easily connect your Sophos Cloud Optix logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's cloud security and compliance posture and improves your cloud security operation capabilities.
15
15
16
16
This is autogenerated content. For changes, contact the solution provider.
Copy file name to clipboardExpand all lines: articles/sentinel/unified-connector-cef-device.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -380,7 +380,7 @@ Configure Palo Alto Networks to forward syslog messages in CEF format to your Mi
380
380
381
381
## PingFederate
382
382
383
-
[Follow these steps](https://docs.pingidentity.com/bundle/pingfederate-102/page/gsn1564002980953.html) to configure PingFederate sending audit log via syslog in CEF format.
383
+
[Follow these steps](https://docs.pingidentity.com/) to configure PingFederate sending audit log via syslog in CEF format.
Copy file name to clipboardExpand all lines: articles/sentinel/unified-connector-syslog-device.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,7 +37,7 @@ This data connector was developed using Cisco ACI Release 1.x.
37
37
38
38
## Cisco Identity Services Engine (ISE)
39
39
40
-
[Follow these instructions](https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_maintain_monitor.html#ID58) to configure remote syslog collection locations in your Cisco ISE deployment.
40
+
[Follow these instructions](https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1.html#ID58) to configure remote syslog collection locations in your Cisco ISE deployment.
0 commit comments