You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-solutions-deploy.md
+18-9Lines changed: 18 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Discover and deploy Microsoft Sentinel out-of-the-box content from Conten
3
3
description: Learn how to find and deploy Sentinel packaged solutions containing data connectors, analytics rules, hunting queries, workbooks, and other content.
4
4
author: cwatson-cat
5
5
ms.topic: how-to
6
-
ms.date: 01/09/2025
6
+
ms.date: 01/14/2025
7
7
ms.author: cwatson
8
8
appliesto:
9
9
- Microsoft Sentinel in the Azure portal
@@ -41,26 +41,35 @@ For more information about other roles and permissions supported for Microsoft S
41
41
42
42
## Discover content
43
43
44
-
The content hub offers the best way to find new content or manage the solutions you already installed.
44
+
The content hub offers the best way to find new content or manage the solutions you already installed.
45
45
46
46
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Content management**, select **Content hub**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Content management** > **Content hub**.
47
47
48
48
The **Content hub** page displays a searchable grid or a list of solutions and standalone content.
49
49
50
-
1.Filter the list displayed, either by selecting specific values from the filters, or entering any part of a content name or description in the **Search**field.
50
+
1.Search for the solutions or standalone content items that you need. Either select specific values from the filters, or enter a search term into the **Search**box. Searches use AI to support fuzzy searches and approximate vocabulary.
51
51
52
-
For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
52
+
When searching, make sure to press **ENTER** to start the search. The number of search results is limited to 50 items, including both solutions and content items found within solutions. If you don't find what you're looking for, try refining the search expression or use different filters.
53
53
54
-
1. Select the **Card view** to view more information about a solution.
54
+
For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
55
55
56
-
Each content item shows categories that apply to it, and solutions show the types of content included. For example, in the following image, the **Cisco Umbrella** solution lists one of its categories as **Security - Cloud Security**, and indicates it includes a data connector, analytics rules, hunting queries, playbooks, and more.
56
+
1. In the list view (:::image type="icon" source="media/sentinel-solutions-deploy/list-view.png" border="false":::), select a solution from the list to view information about the solution as well as the types of content items it includes.
57
57
58
+
Expand a solution in the search or filter results to view the list of content items it includes. The information pane on the side presents detailed information about the content item.
58
59
59
-
#### [Azure portal](#tab/azure-portal)
60
+
#### [Azure portal](#tab/azure-portal)
60
61
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Azure portal.":::
61
62
62
-
#### [Defender portal](#tab/defender-portal)
63
-
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list-defender.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Defender portal.":::
63
+
#### [Defender portal](#tab/defender-portal)
64
+
:::image type="content" source="./media/sentinel-solutions-deploy/solutions-list-defender.png" alt-text="Screenshot of the Microsoft Sentinel content hub in the Defender portal.":::
65
+
66
+
----
67
+
68
+
Alternately, select the card view (:::image type="icon" source="media/sentinel-solutions-deploy/card-view.png" border="false":::) to view solutions presented in a grid. Each card shows the solution name, description, and categories. Select a card to view more information about the solution on the side.
69
+
70
+
To use a content item that's part of a solution, you must install the entire solution. If you've selected a specific content item in the list view, select **Install solution** in the details pane on the side to install the relevant solution.
71
+
72
+
For more information, see [Categories for Microsoft Sentinel out-of-the-box content and solutions](sentinel-solutions.md#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions).
Copy file name to clipboardExpand all lines: articles/sentinel/whats-new.md
+17-2Lines changed: 17 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,8 +4,7 @@ description: Learn about the latest new features and announcement in Microsoft S
4
4
author: yelevin
5
5
ms.author: yelevin
6
6
ms.topic: concept-article
7
-
ms.date: 12/18/2024
8
-
7
+
ms.date: 01/14/2025
9
8
10
9
#Customer intent: As a security team member, I want to stay updated on the latest features and enhancements in Microsoft Sentinel so that I can effectively manage and optimize my organization's security posture.
11
10
@@ -22,6 +21,22 @@ Get notified when this page is updated by copying and pasting the following URL
-[Microsoft Sentinel availability in Microsoft Defender portal](#microsoft-sentinel-availability-in-microsoft-defender-portal)
27
+
28
+
### View granular solution content in the Microsoft Sentinel content hub
29
+
30
+
Now you can view the individual content available in a specific solution directly from the **Content hub**, even before you've installed the solution. This new visibility helps you understand the content available to you, and more easily identify, plan, and install the specific solutions you need.
31
+
32
+
Expand each solution in the Content hub to view included security content. For example:
33
+
34
+
:::image type="content" source="media/sentinel-solutions-deploy/solutions-list.png" alt-text="Screenshot of showing granular content.":::
35
+
36
+
The granular solution content updates also include a generative AI-based search engine that helps you run more robust searches, diving deep into the solution content and returning results for similar terms.
37
+
38
+
For more information, see [Discover content](sentinel-solutions-deploy.md#discover-content).
39
+
25
40
## December 2024
26
41
27
42
-[New SOC optimization recommendation based on similar organizations (Preview)](#new-soc-optimization-recommendation-based-on-similar-organizations-preview)
0 commit comments