You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-solutions-deploy.md
+10-19Lines changed: 10 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Discover and deploy Microsoft Sentinel out-of-the-box content from Conten
3
3
description: Learn how to find and deploy Sentinel packaged solutions containing data connectors, analytics rules, hunting queries, workbooks, and other content.
4
4
author: cwatson-cat
5
5
ms.topic: how-to
6
-
ms.date: 03/01/2024
6
+
ms.date: 01/09/2025
7
7
ms.author: cwatson
8
8
appliesto:
9
9
- Microsoft Sentinel in the Azure portal
@@ -43,37 +43,28 @@ For more information about other roles and permissions supported for Microsoft S
43
43
44
44
## Discover content
45
45
46
-
The content hub offers the best way to find new content or manage the solutions you already installed.
46
+
The content hub offers the best way to find new content or manage the solutions you already installed. Search to find solutions, standalone content items, or content included in solutions. To refine your search, use the filters. For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
47
47
48
-
- For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Content management**, select **Content hub**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Content management** > **Content hub**.
49
48
50
-
The **Content hub** page displays a searchable grid or a list of solutions and standalone content.
51
-
52
-
- Search for the solutions of standalone content items that you need. Either use the **AI search field** or filter by selecting specific values from the filters. Using AI search allows you to perform a fuzzy search and use approximate vocabulary. In the following example, you can see several solutions which include specific content items that match the search criteria.
49
+
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Content management**, select **Content hub**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Content management** > **Content hub**.
53
50
54
-
For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
51
+
The **Content hub** page displays a searchable grid or a list of solutions and standalone content.
55
52
53
+
1. Search for the solutions, standalone content items, or content included in solutions. Use the AI search field or filter by selecting specific values from the filters. Using AI search allows you to perform a fuzzy search and use approximate vocabulary.
56
54
57
-
> [!IMPORTANT]
58
-
> Make sure you press enter to execute the search based on your search string.
59
-
>
60
-
> The number of search results is limited to 50 items, including solutions and content items found within solutions. If you did not find what you are looking for, try to refine your search expression or use additional filters.
61
-
>
55
+
1. Select enter to search based on your search string. The number of search results is limited to 50 items, including solutions and content items found within solutions. If you didn't find what you are looking for, refine your search expression or use additional filters.
62
56
63
-
- Select a solution from the list to view information about the solution as well as the types of content items it includes. For example, in the following image, the **Windows Security Events** solution indicates it includes two data connector, analytics rules, hunting queries, and playbooks.
57
+
1. Select the solution or content item from the list to view information about it.
64
58
65
59
#### [Azure portal](#tab/azure-portal)
66
60
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Azure portal.":::
67
61
68
62
#### [Defender portal](#tab/defender-portal)
69
63
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list-defender.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Defender portal.":::
70
64
71
-
- Expand a solution in the result set using the arrow on the left side to view the list of content items it includes. The information pane on the left presents detailed information about the content item.
72
-
73
-
> [!NOTE]
74
-
> Iif you want to use a content item which is part of a solution, you still need to install the entire solution. Therefore there is an “install solution” button on the information panel of the content item, which will install the solution the content item is part of.
75
-
>
65
+
1. Expand a solution in the result set using the arrow on the left side to view the list of content items it includes. The information pane on the left presents detailed information about the content item.
76
66
67
+
1. To use a content item which is part of a solution, install the solution. Select **install solution** on the information panel of the content item. This action installs the solution that the content item is part of.
77
68
78
69
## Install or update content
79
70
@@ -234,4 +225,4 @@ In this document, you learned how to find and deploy built-in solutions and stan
234
225
235
226
Many solutions include data connectors that you need to configure so that you can start ingesting your data into Microsoft Sentinel. Each data connector has its own set of requirements that are detailed on the data connector page in Microsoft Sentinel.
236
227
237
-
For more information, see [Connect your data source](data-connectors-reference.md).
228
+
For more information, see [Connect your data source](data-connectors-reference.md).
0 commit comments