Skip to content

Commit 9e2976c

Browse files
authored
Merge pull request #285494 from batamig/cust-intents-cat-ii
Adding customer intents - Cat's files no data connectors - needs Cat's review
2 parents ad1b2c2 + 0574fe0 commit 9e2976c

31 files changed

+123
-9
lines changed

articles/sentinel/basic-logs-use-cases.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ appliesto:
99
- Microsoft Sentinel in the Azure portal
1010
- Microsoft Sentinel in the Microsoft Defender portal
1111
ms.collection: usx-security
12+
13+
14+
#Customer intent: As a security analyst, I want to ingest high-volume, verbose logs into a cost-effective storage solution so that I can enhance my threat hunting and incident investigation capabilities.
15+
1216
---
1317
# Log sources to use for Auxiliary Logs ingestion
1418

articles/sentinel/best-practices.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: cwatson-cat
55
ms.author: cwatson
66
ms.topic: conceptual
77
ms.date: 06/28/2024
8+
9+
10+
#Customer intent: As a security operations center (SOC) analyst, I want to implement best practices for deploying and managing a cloud-based SIEM solution so that I can enhance threat detection, incident response, and overall security posture.
11+
812
---
913

1014
# Best practices for Microsoft Sentinel

articles/sentinel/billing-monitor-costs.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ ms.collection: usx-security
1010
appliesto:
1111
- Microsoft Sentinel in the Azure portal
1212
- Microsoft Sentinel in the Microsoft Defender portal
13+
14+
15+
#Customer intent: As a cloud administrator, I want to manage and monitor costs for Microsoft Sentinel so that I can optimize spending and prevent budget overruns.
16+
1317
---
1418

1519
# Manage and monitor costs for Microsoft Sentinel

articles/sentinel/billing-reduce-costs.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
13+
14+
15+
#Customer intent: As a cloud security administrator, I want to optimize the cost of using Microsoft Sentinel so that I can manage my organization's security operations within budget constraints.
16+
1317
---
1418

1519
# Reduce costs for Microsoft Sentinel

articles/sentinel/configure-data-connector.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,10 @@ appliesto:
99
- Microsoft Sentinel in the Azure portal
1010
- Microsoft Sentinel in the Microsoft Defender portal
1111
ms.collection: usx-security
12-
#customer intent: As a security architect or SOC analyst, I want to connect my data source so that I can ingest data into Microsoft Sentinel for security monitoring and threat protection.
12+
13+
14+
#Customer intent: As a security analyst, I want to install and configure data connectors in my SIEM platform so that I can ingest and analyze data from various sources for threat detection and response.
15+
1316
---
1417

1518
# Connect your data sources to Microsoft Sentinel by using data connectors

articles/sentinel/configure-data-retention.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,10 @@ ms.service: microsoft-sentinel
77
ms.topic: tutorial
88
ms.date: 01/05/2023
99
ms.custom: template-tutorial
10-
#Customer intent: As an Azure account administrator, I want to archive older but less used data to save retention costs.
10+
11+
12+
#Customer intent: As a system administrator, I want to configure data retention policies for tables in a Log Analytics workspace so that I can manage Microsoft Sentinel storage costs and ensure compliance with data retention requirements.
13+
1114
---
1215

1316
# Tutorial: Configure a data retention policy for a table in a Log Analytics workspace

articles/sentinel/data-connectors-reference.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
13+
14+
15+
#Customer intent: As a security analyst, I want to find and deploy the appropriate data connectors for Microsoft Sentinel so that I can integrate and monitor various security data sources effectively.
16+
1317
---
1418

1519
# Find your Microsoft Sentinel data connector

articles/sentinel/deploy-overview.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ ms.author: cwatson
66
ms.topic: conceptual
77
ms.date: 06/28/2024
88
ms.service: microsoft-sentinel
9+
10+
11+
#Customer intent: As a SOC architect, I want to deploy Microsoft Sentinel so that I can effectively monitor, detect, and respond to security threats across my organization.
12+
913
---
1014

1115
# Deployment guide for Microsoft Sentinel

articles/sentinel/domain-based-essential-solutions.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,10 @@ appliesto:
99
- Microsoft Sentinel in the Azure portal
1010
- Microsoft Sentinel in the Microsoft Defender portal.
1111
ms.collection: usx-security
12-
#Customer intent: As a security engineer, I want to learn how I can minimize the amount of solution content I have to deploy and manage by using Microsoft essential solutions for Microsoft Sentinel.
12+
13+
14+
#Customer intent: As a security analyst, I want to use ASIM-based domain solutions in Microsoft Sentinel so that I can efficiently normalize and analyze security data across multiple products and reduce alert fatigue.
15+
1316
---
1417

1518
# Advanced Security Information Model (ASIM) based domain solutions for Microsoft Sentinel (preview)

articles/sentinel/enable-sentinel-features-content.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,10 @@ author: cwatson-cat
55
ms.topic: how-to
66
ms.date: 06/18/2024
77
ms.author: cwatson
8-
#Customer intent: As a SOC analyst, I want to enable the Microsoft Sentinel service and the key features and content, so I can get started with my deployment.
8+
9+
10+
#Customer intent: As a security operations analyst, I want to enable and configure Microsoft Sentinel and its key features so that I can monitor and secure my organization's environment effectively.
11+
912
---
1013

1114
# Enable Microsoft Sentinel and initial features and content

0 commit comments

Comments
 (0)