Skip to content

Commit b01fcc2

Browse files
committed
Update sentinel-solutions-deploy.md
1 parent 3336938 commit b01fcc2

File tree

1 file changed

+19
-7
lines changed

1 file changed

+19
-7
lines changed

articles/sentinel/sentinel-solutions-deploy.md

Lines changed: 19 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,9 @@ appliesto:
1818

1919
The Microsoft Sentinel Content hub is your centralized location to discover and manage out-of-the-box (built-in) content. There you find packaged solutions for end-to-end products by domain or industry. You have access to the vast number of standalone contributions hosted in our GitHub repository and feature blades.
2020

21-
- Discover solutions and standalone content with a consistent set of filtering capabilities based on status, content type, support, provider, and category.
21+
- Discover solutions and standalone content using AI based search and filtering based on status, content type, support, provider, and category.
22+
23+
- Expand solutions to learn more about the content items that they comprise of, to better understand the value they provide.
2224

2325
- Install content in your workspace all at once or individually.
2426

@@ -43,25 +45,35 @@ For more information about other roles and permissions supported for Microsoft S
4345

4446
The content hub offers the best way to find new content or manage the solutions you already installed.
4547

46-
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Content management**, select **Content hub**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Content management** > **Content hub**.
48+
- For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Content management**, select **Content hub**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Content management** > **Content hub**.
4749

4850
The **Content hub** page displays a searchable grid or a list of solutions and standalone content.
4951

50-
1. Filter the list displayed, either by selecting specific values from the filters, or entering any part of a content name or description in the **Search** field.
52+
- Search for the solutions of standalone content items that you need. Either use the **AI search field** or filter by selecting specific values from the filters. Using AI search allows you to perform a fuzzy search and use approximate vocabulary. In the following example, you can see several solutions which include specific content items that match the search criteria.
5153

5254
For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
5355

54-
1. Select the **Card view** to view more information about a solution.
5556

56-
Each content item shows categories that apply to it, and solutions show the types of content included. For example, in the following image, the **Cisco Umbrella** solution lists one of its categories as **Security - Cloud Security**, and indicates it includes a data connector, analytics rules, hunting queries, playbooks, and more.
57+
> [!IMPORTANT]
58+
> Make sure you press enter to execute the search based on your search string.
59+
>
60+
> The number of search results is limited to 50 items, including solutions and content items found within solutions. If you did not find what you are looking for, try to refine your search expression or use additional filters.
61+
>
5762
63+
- Select a solution from the list to view information about the solution as well as the types of content items it includes. For example, in the following image, the **Windows Security Events** solution indicates it includes two data connector, analytics rules, hunting queries, and playbooks.
5864

59-
#### [Azure portal](#tab/azure-portal)
65+
#### [Azure portal](#tab/azure-portal)
6066
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Azure portal.":::
6167

6268
#### [Defender portal](#tab/defender-portal)
6369
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list-defender.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Defender portal.":::
6470

71+
- Expand a solution in the result set using the arrow on the left side to view the list of content items it includes. The information pane on the left presents detailed information about the content item.
72+
73+
> [!NOTE]
74+
> Iif you want to use a content item which is part of a solution, you still need to install the entire solution. Therefore there is an “install solution” button on the information panel of the content item, which will install the solution the content item is part of.
75+
>
76+
6577

6678
## Install or update content
6779

@@ -222,4 +234,4 @@ In this document, you learned how to find and deploy built-in solutions and stan
222234

223235
Many solutions include data connectors that you need to configure so that you can start ingesting your data into Microsoft Sentinel. Each data connector has its own set of requirements that are detailed on the data connector page in Microsoft Sentinel.
224236

225-
For more information, see [Connect your data source](data-connectors-reference.md).
237+
For more information, see [Connect your data source](data-connectors-reference.md).

0 commit comments

Comments
 (0)