|
17 | 17 | href: investigate-with-ueba.md
|
18 | 18 | - name: Use automation to respond to threats
|
19 | 19 | href: tutorial-respond-threats-playbook.md
|
20 |
| - - name: Write your first query with Kusto Query Language (Learn module) |
21 |
| - href: /learn/modules/write-first-query-kusto-query-language/ |
22 | 20 | - name: Get started with notebooks and MSTICPy
|
23 | 21 | href: notebook-get-started.md
|
24 | 22 | - name: Create a Power BI report from Microsoft Sentinel
|
25 | 23 | href: powerbi.md
|
26 | 24 | - name: Deploy and monitor decoy honeytokens
|
27 | 25 | href: monitor-key-vault-honeytokens.md
|
28 | 26 | - name: Build and monitor Zero Trust
|
29 |
| - href: /security/zero-trust/integrate/sentinel-solution |
| 27 | + href: /security/zero-trust/integrate/sentinel-solution?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json |
30 | 28 | - name: Integrate with Microsoft Defender for IoT
|
31 | 29 | href: iot-solution.md
|
32 | 30 | - name: Integrate with Microsoft Purview
|
33 | 31 | href: purview-solution.md
|
34 | 32 | - name: Concepts
|
35 | 33 | items:
|
36 |
| - - name: Microsoft Sentinel prerequisites |
37 |
| - href: prerequisites.md |
38 |
| - - name: Costs and billing |
| 34 | + - name: Plan |
39 | 35 | items:
|
40 |
| - - name: Plan costs |
41 |
| - href: billing.md |
42 |
| - - name: Monitor costs |
43 |
| - href: billing-monitor-costs.md |
44 |
| - - name: Reduce costs |
45 |
| - href: billing-reduce-costs.md |
46 |
| - - name: Best practices |
47 |
| - items: |
48 |
| - - name: Overview |
49 |
| - href: best-practices.md |
50 |
| - - name: Workspace architecture |
51 |
| - href: best-practices-workspace-architecture.md |
52 |
| - - name: Data collection |
53 |
| - href: best-practices-data.md |
54 |
| - - name: Partner integrations |
55 |
| - href: partner-integrations.md |
56 |
| - - name: Basic Logs |
57 |
| - href: basic-logs-use-cases.md |
58 |
| - - name: Architecture |
59 |
| - items: |
60 |
| - - name: Roles and permissions |
61 |
| - href: roles.md |
62 |
| - - name: Extend Microsoft Sentinel across workspaces and tenants |
63 |
| - href: extend-sentinel-across-workspaces-tenants.md |
64 |
| - - name: Security baseline |
65 |
| - href: /security/benchmark/azure/baselines/sentinel-security-baseline?toc=%2fazure%2fsentinel%2fTOC.json |
66 |
| - - name: Microsoft Sentinel content |
| 36 | + - name: Prerequisites |
| 37 | + href: prerequisites.md |
| 38 | + - name: Costs and billing |
| 39 | + items: |
| 40 | + - name: Plan costs |
| 41 | + href: billing.md |
| 42 | + - name: Monitor costs |
| 43 | + href: billing-monitor-costs.md |
| 44 | + - name: Reduce costs |
| 45 | + href: billing-reduce-costs.md |
| 46 | + - name: Best practices |
| 47 | + items: |
| 48 | + - name: Overview |
| 49 | + href: best-practices.md |
| 50 | + - name: Workspace architecture |
| 51 | + href: best-practices-workspace-architecture.md |
| 52 | + - name: Data collection |
| 53 | + href: best-practices-data.md |
| 54 | + - name: Partner integrations |
| 55 | + href: partner-integrations.md |
| 56 | + - name: Basic Logs |
| 57 | + href: basic-logs-use-cases.md |
| 58 | + - name: Architecture |
| 59 | + items: |
| 60 | + - name: Roles and permissions |
| 61 | + href: roles.md |
| 62 | + - name: Extend Microsoft Sentinel across workspaces and tenants |
| 63 | + href: extend-sentinel-across-workspaces-tenants.md |
| 64 | + - name: Security baseline |
| 65 | + href: /security/benchmark/azure/baselines/sentinel-security-baseline?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json |
| 66 | + - name: Find solutions and content |
67 | 67 | items:
|
68 | 68 | - name: About Sentinel content
|
69 | 69 | href: sentinel-solutions.md
|
70 | 70 | - name: Content hub catalog
|
71 | 71 | href: sentinel-solutions-catalog.md
|
72 |
| - - name: Data collection and analysis |
| 72 | + - name: Collect data |
73 | 73 | items:
|
74 | 74 | - name: Data collection methods
|
75 | 75 | href: connect-data-sources.md
|
76 | 76 | - name: Classifying data with entities
|
77 | 77 | href: entities.md
|
78 | 78 | - name: Ingestion-time data transformation
|
79 | 79 | href: data-transformation.md
|
80 |
| - - name: Normalization with ASIM |
| 80 | + - name: Write queries with Kusto Query Language |
| 81 | + items: |
| 82 | + - name: Overview |
| 83 | + href: kusto-overview.md |
| 84 | + - name: Query best practices |
| 85 | + href: /azure/data-explorer/kusto/query/best-practices?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json |
| 86 | + - name: SQL to KQL cheat sheet |
| 87 | + href: /azure/data-explorer/kusto/query/sqlcheatsheet?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json |
| 88 | + - name: Splunk to KQL cheat sheet |
| 89 | + href: /azure/data-explorer/kusto/query/splunk-cheat-sheet?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json |
| 90 | + - name: KQL quick reference |
| 91 | + href: /azure/data-explorer/kql-quick-reference?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json |
| 92 | + - name: Other KQL resources |
| 93 | + href: kusto-resources.md |
| 94 | + - name: Normalize data |
81 | 95 | items:
|
82 | 96 | - name: ASIM overview
|
83 | 97 | href: normalization.md
|
84 | 98 | - name: ASIM schemas
|
85 | 99 | href: normalization-about-schemas.md
|
86 | 100 | - name: ASIM parsers
|
87 | 101 | href: normalization-parsers-overview.md
|
88 |
| - - name: Kusto Query Language in Microsoft Sentinel |
89 |
| - items: |
90 |
| - - name: Overview |
91 |
| - href: kusto-overview.md |
92 |
| - - name: Query best practices |
93 |
| - href: /azure/data-explorer/kusto/query/best-practices |
94 |
| - - name: SQL to KQL cheat sheet |
95 |
| - href: /azure/data-explorer/kusto/query/sqlcheatsheet |
96 |
| - - name: Splunk to KQL cheat sheet |
97 |
| - href: /azure/data-explorer/kusto/query/splunk-cheat-sheet |
98 |
| - - name: KQL quick reference |
99 |
| - href: /azure/data-explorer/kql-quick-reference |
100 |
| - - name: Other KQL resources |
101 |
| - href: kusto-resources.md |
102 |
| - - name: Threat intelligence |
| 102 | + - name: Integrate threat intelligence |
103 | 103 | items:
|
104 | 104 | - name: Understand threat intelligence in Microsoft Sentinel
|
105 | 105 | href: understand-threat-intelligence.md
|
106 | 106 | - name: Threat intelligence integrations
|
107 | 107 | href: threat-intelligence-integration.md
|
108 |
| - - name: Threat detection |
| 108 | + - name: Detect threats and analyze data |
109 | 109 | items:
|
110 | 110 | - name: Built-in threat detection rules
|
111 | 111 | href: detect-threats-built-in.md
|
|
119 | 119 | href: fusion.md
|
120 | 120 | - name: Watchlists
|
121 | 121 | href: watchlists.md
|
122 |
| - - name: Threat hunting |
| 122 | + - name: Hunt for threats |
123 | 123 | items:
|
124 | 124 | - name: Overview
|
125 | 125 | href: hunting.md
|
126 | 126 | - name: Jupyter Notebooks
|
127 | 127 | href: notebooks.md
|
128 |
| - - name: Investigate |
| 128 | + - name: Investigate incidents |
129 | 129 | items:
|
130 | 130 | - name: Investigate large datasets
|
131 | 131 | href: investigate-large-datasets.md
|
132 |
| - - name: SOAR |
| 132 | + - name: Automate responses |
133 | 133 | items:
|
134 | 134 | - name: Orchestration, automation, and response
|
135 | 135 | href: automation.md
|
|
139 | 139 | href: automate-responses-with-playbooks.md
|
140 | 140 | - name: Bring your own machine learning
|
141 | 141 | href: bring-your-own-ml.md
|
142 |
| - - name: Microsoft 365 Defender integration |
| 142 | + - name: Integrate Microsoft 365 Defender |
143 | 143 | href: microsoft-365-defender-sentinel-integration.md
|
| 144 | + - name: Integrate SAP |
| 145 | + items: |
| 146 | + - name: Deployment overview |
| 147 | + href: sap/deployment-overview.md |
| 148 | + - name: Deployment prerequisites |
| 149 | + href: sap/prerequisites-for-deploying-sap-continuous-threat-monitoring.md |
144 | 150 | - name: How-tos
|
145 | 151 | items:
|
146 |
| - - name: Design your workspace architecture |
| 152 | + - name: Plan architecture |
147 | 153 | items:
|
148 | 154 | - name: Overview
|
149 | 155 | href: design-your-workspace-architecture.md
|
150 | 156 | - name: Sample workspace designs
|
151 | 157 | href: sample-workspace-designs.md
|
152 |
| - - name: Plan and manage costs |
153 |
| - href: billing.md |
154 | 158 | - name: Manage workspace access
|
155 | 159 | href: resource-context-rbac.md
|
156 | 160 | - name: Migrate to Microsoft Sentinel
|
|
199 | 203 | href: migration-security-operations-center-processes.md
|
200 | 204 | - name: Deploy side-by-side
|
201 | 205 | href: deploy-side-by-side.md
|
202 |
| - - name: Understand MITRE ATT&CK coverage |
203 |
| - href: mitre-coverage.md |
204 |
| - - name: Manage Microsoft Sentinel content |
| 206 | + - name: Find solutions and content |
205 | 207 | items:
|
206 | 208 | - name: Discover and deploy out-of-the-box content
|
207 | 209 | href: sentinel-solutions-deploy.md
|
|
211 | 213 | href: sentinel-solutions-delete.md
|
212 | 214 | - name: Collect data
|
213 | 215 | items:
|
214 |
| - - name: Connect your data source |
| 216 | + - name: Find data connector |
215 | 217 | href: data-connectors-reference.md
|
216 | 218 | - name: Top connectors
|
217 | 219 | expanded: true
|
|
262 | 264 | href: monitor-data-connector-health.md
|
263 | 265 | - name: Integrate Azure Data Explorer
|
264 | 266 | href: store-logs-in-azure-data-explorer.md
|
265 |
| - - name: Use ASIM to normalize data |
| 267 | + - name: Normalize data |
266 | 268 | items:
|
267 | 269 | - name: Use ASIM
|
268 | 270 | href: normalization-about-parsers.md
|
|
272 | 274 | href: normalization-manage-parsers.md
|
273 | 275 | - name: Modify content to use ASIM
|
274 | 276 | href: normalization-modify-content.md
|
275 |
| - - name: Use threat intelligence |
| 277 | + - name: Integrate threat intelligence |
276 | 278 | items:
|
277 | 279 | - name: Connect threat intelligence platforms
|
278 | 280 | href: connect-threat-intelligence-tip.md
|
|
288 | 290 | href: ./monitor-your-data.md
|
289 | 291 | - name: Detect threats and analyze data
|
290 | 292 | items:
|
| 293 | + - name: MITRE ATT&CK coverage |
| 294 | + href: mitre-coverage.md |
291 | 295 | - name: Create threat detection rules
|
292 | 296 | items:
|
293 | 297 | - name: Create a scheduled query rule
|
|
386 | 390 | href: audit-sentinel-data.md
|
387 | 391 | - name: Remove Microsoft Sentinel from your workspaces
|
388 | 392 | href: offboard.md
|
389 |
| -- name: Integrate SAP and Microsoft Sentinel |
390 |
| - items: |
| 393 | + - name: Integrate SAP |
| 394 | + items: |
391 | 395 | - name: Deployment guide
|
392 | 396 | items:
|
393 |
| - - name: Deployment overview |
394 |
| - href: sap/deployment-overview.md |
395 |
| - - name: Deployment prerequisites |
396 |
| - href: sap/prerequisites-for-deploying-sap-continuous-threat-monitoring.md |
397 | 397 | - name: Prepare SAP environment
|
398 | 398 | href: sap/preparing-sap.md
|
399 | 399 | - name: Deploy data connector agent
|
|
412 | 412 | href: sap/sap-solution-deploy-alternate.md
|
413 | 413 | - name: Troubleshooting
|
414 | 414 | items:
|
415 |
| - - name: Troubleshooting SAP solution deployment |
416 |
| - href: sap/sap-deploy-troubleshoot.md |
417 |
| - - name: Configure Transport Management System |
418 |
| - href: sap/configure-transport.md |
419 |
| - - name: Reference |
420 |
| - items: |
421 |
| - - name: SAP solution data reference |
422 |
| - href: sap/sap-solution-log-reference.md |
423 |
| - - name: SAP solution content overview |
424 |
| - href: sap/sap-solution-security-content.md |
425 |
| - - name: Kickstart script reference |
426 |
| - href: sap/reference-kickstart.md |
427 |
| - - name: Container update script reference |
428 |
| - href: sap/reference-update.md |
429 |
| - - name: Systemconfig.ini file reference |
430 |
| - href: sap/reference-systemconfig.md |
| 415 | + - name: Troubleshooting SAP solution deployment |
| 416 | + href: sap/sap-deploy-troubleshoot.md |
| 417 | + - name: Configure Transport Management System |
| 418 | + href: sap/configure-transport.md |
431 | 419 | - name: Reference
|
432 | 420 | items:
|
| 421 | + - name: SAP solution |
| 422 | + items: |
| 423 | + - name: SAP solution data reference |
| 424 | + href: sap/sap-solution-log-reference.md |
| 425 | + - name: SAP solution content overview |
| 426 | + href: sap/sap-solution-security-content.md |
| 427 | + - name: Kickstart script reference |
| 428 | + href: sap/reference-kickstart.md |
| 429 | + - name: Container update script reference |
| 430 | + href: sap/reference-update.md |
| 431 | + - name: Systemconfig.ini file reference |
| 432 | + href: sap/reference-systemconfig.md |
433 | 433 | - name: Service limits
|
434 | 434 | href: sentinel-service-limits.md
|
435 | 435 | - name: Microsoft Sentinel REST-API
|
|
528 | 528 | href: https://azure.microsoft.com/pricing/details/azure-sentinel/
|
529 | 529 | - name: Feature availability for US Government clouds
|
530 | 530 | href: ../security/fundamentals/feature-availability.md
|
| 531 | + - name: Build your skills with Microsoft Learn training |
| 532 | + items: |
| 533 | + - name: Microsoft Sentinel training |
| 534 | + href: /learn/browse/?expanded=azure&products=azure-sentinel |
| 535 | + - name: Kusto Query Language (KQL) training |
| 536 | + href: /learn/browse/?expanded=azure&terms=kusto%20query%20language |
531 | 537 | - name: Archived what's new (older than six months)
|
532 | 538 | href: whats-new-archive.md
|
0 commit comments