Skip to content

Commit aa50d40

Browse files
committed
Adding links and fixing errors
1 parent 1da08f7 commit aa50d40

File tree

3 files changed

+18
-14
lines changed

3 files changed

+18
-14
lines changed

articles/sentinel/sap/configure-audit-log-rules.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ With these rules, you can monitor all audit log events, or get alerts only when
1717
You use two analytics rules to monitor and analyze your SAP audit log data:
1818

1919
- **SAP - Dynamic Deterministic Audit Log Monitor (PREVIEW)**. Alerts on any SAP audit log events with minimal configuration. You can configure the rule for an even lower false-positive rate. [Learn how to configure the rule](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/microsoft-sentinel-for-sap-news-dynamic-sap-security-audit-log/ba-p/3326842).
20-
- **SAP - Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW)**. Alerts on SAP audit log events when anomalies are detected, using machine learning capabilities and with no coding required. [Learn how to configure the rule](#set-up-the-sap---dynamic-deterministic-audit-log-monitor-for-anomaly-detection).
20+
- **SAP - Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW)**. Alerts on SAP audit log events when anomalies are detected, using machine learning capabilities and with no coding required. [Learn how to configure the rule](#set-up-the-sap---dynamic-anomaly-based-audit-log-monitor-alerts-preview-rule-for-anomaly-detection).
2121

2222
The two [SAP Audit log monitor rules](sap-solution-security-content.md#built-in-sap-analytics-rules-for-monitoring-the-sap-audit-log) are delivered as ready to run out of the box, and allow for further fine tuning using the [SAP_Dynamic_Audit_Log_Monitor_Configuration and SAP_User_Config watchlists](sap-solution-security-content.md#available-watchlists).
2323

articles/sentinel/sap/sap-solution-security-content.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ Both SAP audit log monitoring analytics rules share the same data sources and th
4848
A dynamic analytics rule that is intended for covering the entire set of SAP audit log event types which have a deterministic definition in terms of user population, event thresholds.
4949

5050
- [Configure the rule with the SAP_Dynamic_Audit_Log_Monitor_Configuration watchlist](#available-watchlists)
51-
- Learn more about how to [configure the rule](configure-audit-log-rules.md#set-up-the-sap---dynamic-deterministic-audit-log-monitor-for-anomaly-detection) (full procedure)
51+
- Learn more about how to [configure the rule](configure-audit-log-rules.md#set-up-the-sap---dynamic-anomaly-based-audit-log-monitor-alerts-preview-rule-for-anomaly-detection) (full procedure)
5252

5353
#### SAP - Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW)
5454

articles/sentinel/whats-new.md

Lines changed: 16 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,25 @@ If you're looking for items older than six months, you'll find them in the [Arch
2525
>
2626
> You can also contribute! Join us in the [Microsoft Sentinel Threat Hunters GitHub community](https://github.com/Azure/Azure-Sentinel/wiki).
2727
28+
## October 2022
29+
30+
### Out of the box anomaly detection on the SAP audit log (Preview)
31+
32+
The SAP audit log records audit and security events on SAP systems, like failed sign-in attempts or other over 200 security related actions. Customers monitor the SAP audit log and generate alerts and incidents out of the box using Microsoft Sentinel built-in analytics rules.
33+
34+
The Microsoft Sentinel for SAP solution now includes the [**SAP - Dynamic Anomaly Detection analytics** rule](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/anomaly-detection-on-the-sap-audit-log-using-the-microsoft/ba-p/3418709), adding an out of the box capability to identify suspicious anomalies across the SAP audit log events.
35+
36+
Now, together with the existing ability to identify threats deterministically based on predefined patterns and thresholds, customers can easily identify suspicious anomalies in the SAP security log, out of the box, with no coding required.
37+
38+
You can fine-tune the new capability by editing the [SAP_Dynamic_Audit_Log_Monitor_Configuration and SAP_User_Config watchlists](sap-solution-security-content.md#available-watchlists).
39+
40+
Learn more:
41+
- [Learn about the new feature (blog)](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/anomaly-detection-on-the-sap-audit-log-using-the-microsoft/ba-p/3418709)
42+
- [Use the new rule for anomaly detection](sap/configure-audit-log-rules.md#anomaly-detection)
43+
2844
## September 2022
2945

3046
- [Create automation rule conditions based on custom details (Preview)](#create-automation-rule-conditions-based-on-custom-details-preview)
31-
- [Out of the box anomaly detection on the SAP audit log (Preview)](#out-of-the-box-anomaly-detection-on-the-sap-audit-log-preview)
32-
3347
- [Add advanced "Or" conditions to automation rules (Preview)](#add-advanced-or-conditions-to-automation-rules-preview)
3448
- [Heads up: Name fields being removed from UEBA UserPeerAnalytics table](#heads-up-name-fields-being-removed-from-ueba-userpeeranalytics-table)
3549
- [Windows DNS Events via AMA connector (Preview)](#windows-dns-events-via-ama-connector-preview)
@@ -42,16 +56,6 @@ You can set the value of a [custom detail surfaced in an incident](surface-custo
4256

4357
Learn how to [add a condition based on a custom detail](create-manage-use-automation-rules.md#conditions-based-on-custom-details-preview).
4458

45-
### Out of the box anomaly detection on the SAP audit log (Preview)
46-
47-
The SAP audit log records audit and security events on SAP systems, like failed sign-in attempts or other over 200 security related actions. Customers monitor the SAP audit log and generate alerts and incidents out of the box using Microsoft Sentinel built-in analytics rules.
48-
49-
The Microsoft Sentinel for SAP solution now includes the [**SAP - Dynamic Anomaly Detection analytics**](configure-audit-log-rules.md#anomaly-detection) rule, adding an out of the box capability to identify suspicious anomalies across the SAP audit log events.
50-
51-
Now, together with the existing ability to identify threats deterministically based on predefined patterns and thresholds, customers can easily identify suspicious anomalies in the SAP security log, out of the box, with no coding required.
52-
53-
The new capability can be fine-tuned by editing the [SAP_Dynamic_Audit_Log_Monitor_Configuration and SAP_User_Config watchlists](sap-solution-security-content.md#available-watchlists).
54-
5559
### Add advanced "Or" conditions to automation rules (Preview)
5660

5761
You can now add OR conditions to automation rules. Also known as condition groups, these allow you to combine several rules with identical actions into a single rule, greatly increasing your SOC's efficiency.

0 commit comments

Comments
 (0)