You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-solutions-deploy.md
+75-57Lines changed: 75 additions & 57 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,15 +3,15 @@ title: Discover and deploy Microsoft Sentinel out-of-the-box content from Conten
3
3
description: Learn how to find and deploy Sentinel packaged solutions containing data connectors, analytics rules, hunting queries, workbooks, and other content.
4
4
author: austinmccollum
5
5
ms.topic: how-to
6
-
ms.date: 09/29/2023
6
+
ms.date: 02/15/2024
7
7
ms.author: austinmc
8
8
---
9
9
10
10
# Discover and manage Microsoft Sentinel out-of-the-box content
11
11
12
-
The Microsoft Sentinel Content hub is your centralized location to discover and manage out-of-the-box (built-in) content. There you'll find packaged solutions for end-to-end products by domain or industry. You'll also have access to the vast number of standalone contributions hosted in our GitHub repository and feature blades.
12
+
The Microsoft Sentinel Content hub is your centralized location to discover and manage out-of-the-box (built-in) content. There you find packaged solutions for end-to-end products by domain or industry. You have access to the vast number of standalone contributions hosted in our GitHub repository and feature blades.
13
13
14
-
- Discover solutions and standalone content with a consistent set of filtering capabilities based on status, content type, support, provider and category.
14
+
- Discover solutions and standalone content with a consistent set of filtering capabilities based on status, content type, support, provider, and category.
15
15
16
16
- Install content in your workspace all at once or individually.
17
17
@@ -25,71 +25,71 @@ If you're a partner who wants to create your own solution, see the [Microsoft Se
25
25
26
26
## Prerequisites
27
27
28
-
In order to install, update and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level.
28
+
In order to install, update, and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level.
29
29
30
30
For more information about other roles and permissions supported for Microsoft Sentinel, see [Permissions in Microsoft Sentinel](roles.md).
31
31
32
32
33
33
## Discover content
34
34
35
-
The content hub offers the best way to find new content or manage the solutions you already have installed.
35
+
The content hub offers the best way to find new content or manage the solutions you already installed.
36
36
37
-
1.From the Microsoft Sentinel navigation menu, under **Content management**, select **Content hub**.
37
+
1.For Microsoft Sentinel in the [Azure portal](https://portal.microsoft.com), under **Content management**, select **Content hub**.
38
38
39
-
1. The **Content hub** page displays a searchable grid or list of solutions and standalone content.
39
+
The **Content hub** page displays a searchable grid or list of solutions and standalone content.
40
40
41
-
Filter the list displayed, either by selecting specific values from the filters, or entering any part of a content name or description in the **Search** field.
41
+
1. Filter the list displayed, either by selecting specific values from the filters, or entering any part of a content name or description in the **Search** field.
42
42
43
43
For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
44
44
45
-
> [!TIP]
46
-
> If a solution that you've deployed has updates since you deployed it, the list view will have a blue up arrow in the status column, and will be included in the **Updates** blue up arrow count at the top of the page.
47
-
>
45
+
1. Select the **Card view** to view more information about a solution.
48
46
49
-
Each content item shows categories that apply to it, and solutions show the types of content included.
47
+
Each content item shows categories that apply to it, and solutions show the types of content included. For example, in the following image, the **Cisco Umbrella** solution lists one of its categories as **Security - Cloud Security**, and indicates it includes a data connector, analytics rules, hunting queries, playbooks, and more.
50
48
51
-
For example, in the following image, the **Cisco Umbrella** solution lists one of its categories as **Security - Cloud Security**, and indicates it includes a data connector, analytics rules, hunting queries, playbooks, and more.
52
-
53
-
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list.png" alt-text="Screenshot of the Microsoft Sentinel content hub.":::
49
+
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list.png" alt-text="Screenshot of the Microsoft Sentinel content hub.":::
54
50
55
51
56
52
## Install or update content
57
53
58
-
Standalone content and solutions can be installed individually or all together in bulk. For more information on bulk operations, see [Bulk install and update content](#bulk-install-and-update-content) in the next section. Here's an example showing the install of an individual solution.
54
+
Install standalone content and solutions individually or all together in bulk. For more information on bulk operations, see [Bulk install and update content](#bulk-install-and-update-content) in the next section.
55
+
56
+
If a solution that you deployed has updates since you last deployed it, the list view shows **Update** in the status column. The solution is also included in the **Updates** count at the top of the page.
57
+
58
+
Here's an example showing the install of an individual solution.
59
59
60
-
1. In the content hub, to view more information about a solution switch to **Card view**.
60
+
1. In the **Content hub**, search for and select the solution.
61
61
62
-
1.Then select **View details** to initiate steps for installation.
62
+
1.On the solutions details pane, from the bottom right-hand side, select **View details**.
63
63
64
-
1. On the solution details page, select **Create** or **Update** to start the solution wizard. On the **Basics** tab, enter the subscription, resource group, and workspace to deploy the solution. For example:
64
+
1. Select **Create** or **Update**.
65
+
1. On the **Basics** tab, enter the subscription, resource group, and workspace to deploy the solution. For example:
65
66
66
67
:::image type="content" source="media/sentinel-solutions-deploy/wizard-basics.png" alt-text="Screenshot of a solution installation wizard, showing the Basics tab.":::
67
68
68
-
1. Select **Next** to cycle through the remaining tabs (corresponding to the components included in the solution), where you can learn about, and in some cases configure, each of the content components.
69
+
1. Select **Next** to go through the remaining tabs to learn about, and in some cases configure, each of the content components.
69
70
70
-
> [!NOTE]
71
-
> The tabs displayed for you correspond with the content offered by the solution. Different solutions may have different types of content, so you may not see all the same tabs in every solution.
72
-
>
73
-
> You may also be prompted to enter credentials to a third party service so that Microsoft Sentinel can authenticate to your systems. For example, with playbooks, you may want to take response actions as prescribed in your system.
74
-
>
71
+
The tabs correspond with the content offered by the solution. Different solutions might have different types of content, so you might not see the same tabs in every solution.
75
72
76
-
1. Finally, in the **Review + create** tab, wait for the `Validation Passed` message, then select **Create** or **Update** to deploy the solution. You can also select the **Download a template for automation** link to deploy the solution as code.
73
+
You might also be prompted to enter credentials to a third party service so that Microsoft Sentinel can authenticate to your systems. For example, with playbooks, you might want to take response actions as prescribed in your system.
77
74
78
-
1. Each content type within the solution may require additional steps to configure. For more information, see [Enable content items in a solution](#enable-content-items-in-a-solution).
75
+
1. In the **Review + create** tab, wait for the `Validation Passed` message.
76
+
1. Select **Create** or **Update** to deploy the solution. You can also select the **Download a template for automation** link to deploy the solution as code.
79
77
80
-
## Bulk install and update content
78
+
Each content type within the solution might require more steps to configure. For more information, see [Enable content items in a solution](#enable-content-items-in-a-solution).
81
79
82
-
Content hub supports a list view in addition to the default card view. Multiple solutions and standalone content can be selected with this view to install and update them all at once. Standalone content is kept up-to-date automatically. Any active or
83
-
custom content created based on solutions or standalone content installed from content hub remains untouched.
80
+
## Bulk install and update content
84
81
85
-
1. To install and/or update items in bulk, change to the list view.
82
+
Content hub supports a list view in addition to the default card view. Select the list view to install multiple solutions and standalone content all at once. Standalone content is kept up-to-date automatically. Any active or custom content created based on solutions or standalone content installed from content hub remains untouched.
86
83
87
-
1. The list view is paginated, so choose a filter to ensure the content you want to bulk install are in view. Select their checkboxes and click the **Install/Update** button.
84
+
1. To install or update items in bulk, change to the list view.
85
+
1. Search for or filter to find the content that you want to install or update in bulk.
86
+
1. Select the checkbox for each solution or standalone content that you want to install or update.
87
+
1. Select the **Install/Update** button.
88
88
:::image type="content" source="media/sentinel-solutions-deploy/bulk-install-update.png" alt-text="Screenshot of solutions list view with multiple solutions selected and in progress for installation." lightbox="media/sentinel-solutions-deploy/bulk-install-update.png":::
89
89
90
-
1. The content hub interface will indicate *in progress* for installs and updates. Azure notifications will also indicate the action taken. If a solution or standalone content that was already installed or updated was selected, no action will be taken on that item and it won't interfere with the update and install of the other items.
90
+
If a solution or standalone content you selected was already installed or updated, no action is taken on that item. It doesn't interfere with the update and install of the other items.
91
91
92
-
1.Check each installed solution's **Manage**view. Content types within the solution may require additional steps to configure. For more information, see [Enable content items in a solution](#enable-content-items-in-a-solution).
92
+
1.Select **Manage**for each solution you installed. Content types within the solution might require more information for you to configure. For more information, see [Enable content items in a solution](#enable-content-items-in-a-solution).
93
93
94
94
## Enable content items in a solution
95
95
@@ -106,64 +106,82 @@ Centrally manage content items for installed solutions from the content hub.
106
106
107
107
1. Select a content item to get started.
108
108
109
-
### Management options for each content type
110
-
Below are some tips on how to interact with various content types when managing a solution.
109
+
### Manage each content type
110
+
111
+
The following sections provide some tips on how to work with the different content types as you manage a solution.
111
112
112
113
#### Data connector
114
+
115
+
To connect a data connector, complete the configuration steps.
113
116
1. Select **Open connector page**.
114
117
1. Complete the data connector configuration steps.
115
118
116
119
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-data-connector-open-connector.png" alt-text="Screenshot of data connector content item for Azure Activity solution where status is disconnected.":::
117
120
118
-
1.After you configure the data connector and logs are detected, the status will change to **Connected**.
121
+
After you configure the data connector and logs are detected, the status changes to **Connected**.
119
122
120
123
#### Analytics rule
121
-
1. View the template in the analytics template gallery.
122
-
1. If the template hasn't been used yet, select **Open** > **Create rule** and follow the steps to enable the analytics rule.
123
-
1. Once created, the number of active rules created from the template is shown in the **Created content** column.
124
-
1. Click the active rules link, in this example **2 items**, to edit the existing rule.
125
124
126
-
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-analytics-rule.png" alt-text="Screenshot of analytics rule content item in solution for Azure Activity." lightbox="media/sentinel-solutions-deploy/manage-solution-analytics-rule.png":::
125
+
Create a rule from a template or edit an existing rule.
126
+
127
+
1. View the template in the analytics template gallery.
128
+
1. If the template isn't used yet, select **Open** > **Create rule** and follow the steps to enable the analytics rule.
129
+
130
+
After you create a rule, the number of active rules created from the template is shown in the **Created content** column.
131
+
1. Select the active rules link to edit the existing rule. For example, the active rule link in the following image is under **Content created** and shows **2 items**.
132
+
133
+
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-analytics-rule.png" alt-text="Screenshot of analytics rule content item in solution for Azure Activity." lightbox="media/sentinel-solutions-deploy/manage-solution-analytics-rule.png":::
127
134
128
135
#### Hunting query
129
-
1. To start searching right away, select **Run query** from the details page for quick results.
136
+
137
+
Run the provided hunting query or customize it.
138
+
139
+
1. To start searching right away, select **Run query** from the details page for quick results.
130
140
131
141
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-hunting-query.png" alt-text="Screenshot of cloned hunting query content item in solution for Azure Activity." lightbox="media/sentinel-solutions-deploy/manage-solution-hunting-query.png":::
132
142
133
-
1. To customize your hunting query, select the link, in this case **Common deployed resources**, in the **Content name** column.
134
-
1. This brings you to the hunting gallery where you can create a clone of the read-only hunting query template by accessing the ellipses menu. Hunting queries created in this way will display as items in the content hub **Created content** column.
143
+
1. To customize your hunting query, select the link in the **Content name** column.
144
+
145
+
From the hunting gallery, you can create a clone of the read-only hunting query template by going to the ellipses menu. Hunting queries created in this way display as items in the content hub **Created content** column.
135
146
136
147
#### Workbook
137
-
1. Select **View template** to open the workbook and see the visualizations.
138
-
1. To create an instance of the workbook template select **Save**.
148
+
149
+
To customize a workbook created from a template, create an instance of a workbook.
150
+
151
+
1. Select **View template** to open the workbook and see the visualizations.
152
+
1. Select **Save** to create an instance of the workbook template.
139
153
1. View your saved customizable workbook by selecting **View saved workbook**.
140
154
1. From the content hub, select the **1 item** link in the **Created content** column to manage the workbook.
141
155
142
156
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-workbook.png" alt-text="Screenshot of saved workbook item in solution for Azure Activity." lightbox="media/sentinel-solutions-deploy/manage-solution-workbook.png" :::
143
157
144
-
#### Parser
158
+
#### Parser
159
+
145
160
When a solution is installed, any parsers included are added as workspace functions in Log Analytics.
146
-
1. Select **Load the function code** to open Log Analytics and view or run the function code.
161
+
162
+
1. Select **Load the function code** to open Log Analytics and view or run the function code.
147
163
1. Select **Use in editor** to open Log Analytics with the parser name ready to add to your custom query.
148
164
149
165
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-parser.png" alt-text="Screenshot of parser content type in a solution." lightbox="media/sentinel-solutions-deploy/manage-solution-parser.png":::
150
166
151
167
#### Playbook
152
-
1. Select the **Content name** link of the playbook, in this example **BatchImportToSentinel**.
153
-
1. This playbook template will populate the search field. From the results choose the template and select **Create playbook**.
154
-
1. Once created, the active playbook is shown in the **Created content** column.
155
-
1. Click the active playbook **1 item** link to manage the playbook.
156
168
157
-
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-playbook.png" alt-text="Screenshot of playbook type content type in a solution." lightbox="media/sentinel-solutions-deploy/manage-solution-playbook.png":::
169
+
Create a playbook from a template.
158
170
171
+
1. Select the **Content name** link of the playbook.
172
+
1. Choose the template and select **Create playbook**.
173
+
1. After the playbook is created, the active playbook is shown in the **Created content** column.
174
+
1. Select the active playbook **1 item** link to manage the playbook.
175
+
176
+
:::image type="content" source="media/sentinel-solutions-deploy/manage-solution-playbook.png" alt-text="Screenshot of playbook type content type in a solution." lightbox="media/sentinel-solutions-deploy/manage-solution-playbook.png":::
159
177
160
178
## Find the support model for your content
161
179
162
180
Each solution and standalone content item explains its support model on its details pane, in the **Support** box, where either **Microsoft** or a partner's name is listed. For example:
163
181
164
182
:::image type="content" source="media/sentinel-solutions-deploy/find-support-details.png" alt-text="Screenshot of where you can find your support model for your solution." lightbox="media/sentinel-solutions-deploy/find-support-details.png":::
165
183
166
-
When contacting support, you may need other details about your solution, such as a publisher, provider, and plan ID values. You can find each of these on the details page, on the **Usage information & support** tab. For example:
184
+
When contacting support, you might need other details about your solution, such as a publisher, provider, and plan ID values. Find this information on the details page in the **Usage information & support** tab.
167
185
168
186
:::image type="content" source="media/sentinel-solutions-deploy/usage-support.png" alt-text="Screenshot of usage and support details for a solution.":::
169
187
@@ -174,8 +192,8 @@ In this document, you learned how to find and deploy built-in solutions and stan
174
192
- Learn more about [Microsoft Sentinel solutions](sentinel-solutions.md).
175
193
- See the full Microsoft Sentinel solutions catalog in the [Azure Marketplace](https://azuremarketplace.microsoft.com/marketplace/apps?filters=solution-templates&page=1&search=sentinel).
176
194
- Find domain specific solutions in the [Microsoft Sentinel content hub catalog](sentinel-solutions-catalog.md).
177
-
-[Delete installed Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions-delete.md)
195
+
-[Delete installed Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions-delete.md).
178
196
179
-
Many solutions include data connectors that you'll need to configure so that you can start ingesting your data into Microsoft Sentinel. Each data connector will have its own set of requirements, detailed on the data connector page in Microsoft Sentinel.
197
+
Many solutions include data connectors that you need to configure so that you can start ingesting your data into Microsoft Sentinel. Each data connector has its own set of requirements that are detailed on the data connector page in Microsoft Sentinel.
180
198
181
199
For more information, see [Connect your data source](data-connectors-reference.md).
0 commit comments