You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-content-centralize.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -76,13 +76,13 @@ Specific impact to the gallery content templates for each of these galleries are
76
76
77
77
Here's an example of an Analytics rule before and after the centralization changes and the tool has run.
78
78
- The active Analytics rule won't change at all. We can see it's based on an Analytics rule template that will be retired.
79
-
:::image type="content" source="media/sentinel-content-centralize/before-tool-analytic-rule-active-2.png" alt-text="This screenshot shows an active Analytics rule before centralization changes.":::
79
+
:::image type="content" source="media/sentinel-content-centralize/before-tool-analytic-rule-active-2.png" alt-text="This screenshot shows an active Analytics rule before centralization changes." lightbox="media/sentinel-content-centralize/before-tool-analytic-rule-active-2.png":::
80
80
81
81
- This screenshot shows an Analytics rule template that will be retired.
82
-
:::image type="content" source="media/sentinel-content-centralize/before-tool-analytic-rule-templates-2.png" alt-text="This screenshot shows the Analytics rule template that will be retired.":::
82
+
:::image type="content" source="media/sentinel-content-centralize/before-tool-analytic-rule-templates-2.png" alt-text="This screenshot shows the Analytics rule template that will be retired." lightbox="media/sentinel-content-centralize/before-tool-analytic-rule-templates-2.png":::
83
83
84
84
- After the tool has been run to reinstate the Analytics rule template, the source changes to the solution it's reinstated from.
85
-
:::image type="content" source="media/sentinel-content-centralize/after-tool-analytic-rule-template-2.png" alt-text="This screenshot shows the Analytics rule template after being reinstated from the Content hub Azure Active Directory solution.":::
85
+
:::image type="content" source="media/sentinel-content-centralize/after-tool-analytic-rule-template-2.png" alt-text="This screenshot shows the Analytics rule template after being reinstated from the Content hub Azure Active Directory solution." lightbox="media/sentinel-content-centralize/after-tool-analytic-rule-template-2.png":::
86
86
87
87
## Action needed
88
88
- Starting now, install new OOTB content from Content hub and update solutions as needed to have the latest version of templates.
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-solutions-deploy.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -161,11 +161,11 @@ When a solution is installed, any parsers included are added as workspace functi
161
161
162
162
## Find the support model for your content
163
163
164
-
Each solution explains its support model on the solution's details pane, in the **Support** box, where either **Microsoft** or a partner's name is listed. For example:
164
+
Each solution and standalone content item explains its support model on its details pane, in the **Support** box, where either **Microsoft** or a partner's name is listed. For example:
165
165
166
166
:::image type="content" source="media/sentinel-solutions-deploy/find-support-details.png" alt-text="Screenshot of where you can find your support model for your solution." lightbox="media/sentinel-solutions-deploy/find-support-details.png":::
167
167
168
-
When contacting support, you may need other details about your solution, such as a publisher, provider, and plan ID values. You can find each of these on the solution's details page, on the **Usage information & support** tab. For example:
168
+
When contacting support, you may need other details about your solution, such as a publisher, provider, and plan ID values. You can find each of these on the details page, on the **Usage information & support** tab. For example:
169
169
170
170
:::image type="content" source="media/sentinel-solutions-deploy/usage-support.png" alt-text="Screenshot of usage and support details for a solution.":::
Copy file name to clipboardExpand all lines: articles/sentinel/sentinel-solutions.md
+15-14Lines changed: 15 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: About Microsoft Sentinel content and solutions | Microsoft Docs
3
3
description: This article describes Microsoft Sentinel content and solutions, which customers can use to find data analysis tools packaged together with data connectors.
4
4
author: cwatson-cat
5
5
ms.topic: conceptual
6
-
ms.date: 01/05/2023
6
+
ms.date: 02/13/2023
7
7
ms.author: cwatson
8
8
---
9
9
@@ -22,19 +22,19 @@ Content in Microsoft Sentinel includes any of the following types:
22
22
-**[Watchlists](watchlists.md)** support the ingestion of *specific* data for enhanced threat detection and reduced alert fatigue
23
23
-**[Playbooks and Azure Logic Apps custom connectors](automate-responses-with-playbooks.md)** provide features for automated investigation, remediation, and response scenarios in Microsoft Sentinel
24
24
25
-
Microsoft Sentinel *solutions* are packages of Microsoft Sentinel content or Microsoft Sentinel API integrations, which fulfill an end-to-end product, domain, or industry vertical scenario in Microsoft Sentinel.
25
+
Microsoft Sentinel offers these content types as *solutions*and *standalone* items. *Solutions*are packages of Microsoft Sentinel content or Microsoft Sentinel API integrations, which fulfill an end-to-end product, domain, or industry vertical scenario in Microsoft Sentinel. Both solutions and standalone items are discoverable and managed from the Content hub.
26
26
27
-
You can either customize out-of-the-box content for your own needs, or you can create your own solution with content to share with others in the community. For more information, see the [Microsoft Sentinel Solutions Build Guide](https://aka.ms/sentinelsolutionsbuildguide) for solutions' authoring and publishing.
27
+
You can either customize out-of-the-box (OOTB) content for your own needs, or you can create your own solution with content to share with others in the community. For more information, see the [Microsoft Sentinel Solutions Build Guide](https://aka.ms/sentinelsolutionsbuildguide) for solutions' authoring and publishing.
28
28
29
29
> [!IMPORTANT]
30
30
>
31
31
> The Microsoft Sentinel **Content hub** and solutions are currently in **PREVIEW**, as are all individual solution packages. See the [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) for additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
32
32
33
33
## Discover and manage Microsoft Sentinel content
34
34
35
-
Use the Microsoft Sentinel **Content hub** to centrally discover and install out-of-the-box (built-in) content.
35
+
Use the Microsoft Sentinel **Content hub** to centrally discover and install out-of-the-box (OOTB) content.
36
36
37
-
The Microsoft Sentinel Content Hub provides in-product discoverability, single-step deployment, and enablement of end-to-end product, domain, and/or vertical out-of-the-box solutions and content in Microsoft Sentinel.
37
+
The Microsoft Sentinel Content hub provides in-product discoverability, single-step deployment, and enablement of end-to-end product, domain, and/or vertical OOTB solutions and content in Microsoft Sentinel.
38
38
39
39
- In the **Content hub**, filter by [categories](#categories-for-microsoft-sentinel-out-of-the-box-content-and-solutions) and other parameters, or use the powerful text search, to find the content that works best for your organization's needs. The **Content hub** also indicates the [support model](#support-models-for-microsoft-sentinel-out-of-the-box-content-and-solutions) applied to each piece of content, as some content is maintained by Microsoft and others are maintained by partners or the community.
40
40
@@ -52,9 +52,9 @@ The solutions experience, powered by [Azure Marketplace](https://azuremarketplac
52
52
53
53
-**Integrations** include services or tools built using Microsoft Sentinel or Azure Log Analytics APIs that support integrations between Azure and existing customer applications, or migrate data, queries, and more, from those applications into Microsoft Sentinel.
54
54
55
-
You can also use solutions to install packages of out-of-the-box content in a single step, where the content is often ready to use immediately. Providers and partners use Sentinel solutions to add value to their customers' investments by delivering combined product, domain, or vertical value.
55
+
You can also use solutions to install packages of out-of-the-box (OOTB) content in a single step, where the content is often ready to use immediately. Providers and partners use Sentinel solutions to add value to their customers' investments by delivering combined product, domain, or vertical value.
56
56
57
-
Use the Content hub to centrally discover and deploy solutions and out-of-the-box content in a scenario-driven manner.
57
+
Use the Content hub to centrally discover and deploy solutions and OOTB content in a scenario-driven manner.
58
58
59
59
For more information, see:
60
60
@@ -64,7 +64,7 @@ For more information, see:
64
64
65
65
## Categories for Microsoft Sentinel out-of-the-box content and solutions
66
66
67
-
Microsoft Sentinel out-of-the-box content can be applied with one or more of the following categories. In the **Content hub**, select the categories you want to view to change the content displayed.
67
+
Microsoft Sentinel out-of-the-box content can be applied with one or more of the following categories. In the **Content hub**, select the categories you want to view to change the content displayed. You can discover community delivered items centrally in Content hub as standalone content or solutions.
68
68
69
69
### Domain categories
70
70
@@ -123,16 +123,17 @@ Each piece of content or solution has one of the following content sources:
123
123
124
124
|Content source |Description |
125
125
|---------|---------|
126
-
|**Content hub**|Content or solutions deployed by the content hub that support lifecycle management |
127
-
|**Custom**| Content or solutions you've customized in your workspace |
128
-
|**Gallery content**| Content or solutions from the gallery that don't support lifecycle management |
129
-
|**Repositories**| Content or solutions from a repository connected to your workspace |
126
+
|**Content hub**|Solutions deployed by the Content hub that support lifecycle management |
127
+
|**Standalone**|Standalone content deployed by the Content hub that is automatically kept up-to-date |
128
+
|**Custom**|Content or solutions you've customized in your workspace |
129
+
|**Gallery content**|Content from the feature galleries that don't support lifecycle management. This content source is retiring soon. For more information see [OOTB content centralization changes](sentinel-content-centralize.md). |
130
+
|**Repositories**|Content or solutions from a repository connected to your workspace |
130
131
131
132
## Next steps
132
133
133
-
After you've learned about Microsoft Sentinel content, start managing content and solutions in your Microsoft Sentinel workspace.
134
+
After you've learned about Microsoft Sentinel content, discover and install solutions and standalone content from the **Content hub** in your Microsoft Sentinel workspace.
134
135
135
-
Discover and install solutions from the Microsoft Sentinel **Content hub**. For more information, see:
136
+
For more information, see:
136
137
137
138
-[Centrally discover and deploy out-of-the-box content and solutions (Public preview)](sentinel-solutions-deploy.md)
138
139
- Microsoft Sentinel solutions catalog in the [Azure Marketplace](https://azuremarketplace.microsoft.com/marketplace/apps?filters=solution-templates&page=1&search=sentinel)
0 commit comments