Skip to content

Commit cc7b408

Browse files
remove preview for GA
1 parent 1726882 commit cc7b408

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

articles/sentinel/siem-migration.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,12 @@ author: austinmccollum
66
ms.topic: how-to
77
ms.date: 3/11/2024
88
ms.author: austinmc
9+
appliesto:
10+
- Microsoft Sentinel in the Azure portal
911
#customer intent: As an SOC administrator, I want to use the SIEM migration experience so I can migrate to Microsoft Sentinel.
1012
---
1113

12-
# Migrate to Microsoft Sentinel with the SIEM migration experience (preview)
14+
# Migrate to Microsoft Sentinel with the SIEM migration experience
1315

1416
Migrate your SIEM to Microsoft Sentinel for all your security monitoring use cases. Automated assistance from the SIEM Migration experience simplifies your migration.
1517

@@ -39,27 +41,25 @@ You need the following on the target, Microsoft Sentinel:
3941

4042
At the core of Splunk detection rules is the Search Processing Language (SPL). The SIEM migration experience systematically translates SPL to Kusto query language (KQL) for each Splunk rule. Carefully review translations and make adjustments to ensure migrated rules function as intended in your Microsoft Sentinel workspace. For more information on the concepts important in translating detection rules, see [migrate Splunk detection rules](migration-splunk-detection-rules.md).
4143

42-
Capabilities in public preview:
44+
Current capabilities:
4345

4446
- Translate simple queries with a single data source
4547
- Direct translations listed in the article, [Splunk to Kusto cheat sheet](/azure/data-explorer/kusto/query/splunk-cheat-sheet)
4648
- Review translated query error feedback with edit capability to save time in the detection rule translation process
49+
- Translated queries feature a completeness status with translation states
4750

4851
Here are some of the priorities that are important to us as we continue to develop the translation technology:
4952

5053
- Splunk Common Information Model (CIM) to Microsoft Sentinel's Advanced Security Information Model (ASIM) translation support
51-
- Translated queries feature a completeness status with translation states
52-
- Multiple data sources and index
53-
- Rule correlations
54-
- Support for macros
55-
- Support for lookups
56-
- Complex queries with joins
54+
- Translation of complex correlation logic that queries and correlates events across multiple data sources
55+
- Support for Splunk macros
56+
- Support for Splunk lookups
5757

5858
## Start the SIEM migration experience
5959

6060
1. Navigate to Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Content management**, select **Content hub**.
6161

62-
1. Select **SIEM Migration (Preview)**.
62+
1. Select **SIEM Migration**.
6363

6464
:::image type="content" source="media/siem-migration/siem-migration-experience.png" alt-text="Screenshot showing content hub with menu item for the SIEM migration experience.":::
6565

0 commit comments

Comments
 (0)