Skip to content

Commit da5a02e

Browse files
committed
updates
1 parent c4c851a commit da5a02e

File tree

3 files changed

+45
-47
lines changed

3 files changed

+45
-47
lines changed

articles/sentinel/TOC.yml

Lines changed: 38 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
items:
66
- name: What is Microsoft Sentinel?
77
href: overview.md
8-
- name: What is Microsoft Sentinel data lake (Preview)?
8+
- name: What is Microsoft Sentinel data lake (preview)?
99
href: graph/sentinel-lake-overview.md
1010
displayName: data lake
1111
- name: What's new
@@ -14,46 +14,44 @@
1414
href: best-practices.md
1515
- name: Experience in Defender portal
1616
href: microsoft-sentinel-defender-portal.md
17-
- name: Microsoft Sentinel data lake (Preview)
17+
- name: Data lake exploration (preview)
1818
items:
19-
- name: Data lake exploration
19+
- name: KQL for the Microsoft Sentinel data lake (preview)
2020
items:
21-
- name: KQL for the Microsoft Sentinel data lake (Preview)
22-
items:
23-
- name: Overview
24-
href: graph/kql-overview.md
25-
displayName: data lake
26-
- name: Run KQL queries (Preview)
27-
href: graph/kql-queries.md
28-
displayName: data lake
29-
- name: Sample data lake queries (Preview)
30-
href: graph/kql-samples.md
31-
displayName: data lake
32-
- name: Create KQL jobs (Preview)
33-
href: graph/kql-jobs.md
34-
displayName: data lake
35-
- name: Manage KQL jobs (Preview)
36-
href: graph/kql-manage-jobs.md
37-
displayName: data lake
38-
- name: Troubleshoot KQL for the lake (Preview)
39-
href: graph/kql-troubleshoot.md
40-
displayName: data lake
41-
- name: Notebooks for data lake exploration (Preview)
42-
items:
43-
- name: Overview
44-
href: graph/notebooks-overview.md
45-
displayName: data lake
46-
- name: Run notebooks (Preview)
47-
href: graph/notebooks.md
48-
displayName: data lake
49-
- name: Microsoft Sentinel provider class reference (Preview)
50-
href: graph/sentinel-provider-class-reference.md
51-
displayName: data lake
52-
- name: Create and manage notebook jobs (Preview)
53-
href: graph/notebook-jobs.md
54-
displayName: data lake
55-
- name: Notebook examples for data lake exploration (Preview)
56-
href: graph/notebook-examples.md
21+
- name: Overview
22+
href: graph/kql-overview.md
23+
displayName: data lake
24+
- name: Run KQL queries
25+
href: graph/kql-queries.md
26+
displayName: data lake
27+
- name: Sample data lake queries
28+
href: graph/kql-samples.md
29+
displayName: data lake
30+
- name: Create KQL jobs
31+
href: graph/kql-jobs.md
32+
displayName: data lake
33+
- name: Manage KQL jobs
34+
href: graph/kql-manage-jobs.md
35+
displayName: data lake
36+
- name: Troubleshoot KQL for the lake
37+
href: graph/kql-troubleshoot.md
38+
displayName: data lake
39+
- name: Notebooks for data lake exploration (preview)
40+
items:
41+
- name: Overview
42+
href: graph/notebooks-overview.md
43+
displayName: data lake
44+
- name: Run notebooks
45+
href: graph/notebooks.md
46+
displayName: data lake
47+
- name: Microsoft Sentinel provider class reference
48+
href: graph/sentinel-provider-class-reference.md
49+
displayName: data lake
50+
- name: Create and manage notebook jobs
51+
href: graph/notebook-jobs.md
52+
displayName: data lake
53+
- name: Notebook examples for data lake exploration
54+
href: graph/notebook-examples.md
5755
- name: Plan
5856
items:
5957
- name: Deployment planning guide
@@ -97,7 +95,7 @@
9795
href: quickstart-onboard.md
9896
- name: Connect Microsoft Sentinel to the Defender portal
9997
href: /unified-secops-platform/microsoft-sentinel-onboard?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
100-
- name: Onboard to Microsoft Sentinel data lake (Preview)
98+
- name: Onboard to Microsoft Sentinel data lake (preview)
10199
href: graph/sentinel-lake-onboarding.md
102100
displayName: data lake
103101
- name: Set up connectors for the Microsoft Sentinel data lake

articles/sentinel/basic-logs-use-cases.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
---
2-
title: When to use data lake in Microsoft Sentinel
3-
description: Learn what log sources might be appropriate for the Microsoft Sentinel data lake and what attributes to look for, to decide about other sources.
2+
title: When to use the Microsoft Sentinel data lake
3+
description: Learn what log sources might be appropriate for the Microsoft Sentinel data lake and what attributes to look for, to decide about other sources.
44
author: EdB-MSFT
55
ms.author: edbaynash
66
ms.topic: conceptual
7-
ms.date: 07/07/2025
7+
ms.date: 07/15/2025
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -16,11 +16,12 @@ ms.collection: usx-security
1616
---
1717
# Log sources to use for the Microsoft Sentinel data lake
1818

19-
This article highlights log sources to consider configuring as data lake tier only when enabling a connector. Before choosing a tier for which to configure a given table, do the research to see which is most appropriate. For more information about data categories and data tiers, see [Data tiers in Microsoft Sentinel](log-plans.md).
19+
This article highlights log sources to consider configuring as data lake tier only when enabling a connector. Before choosing a tier for which to configure a given table, check which tier is most appropriate for your use case. For more information about data categories and data tiers, see [Log retention plans in Microsoft Sentinel](log-plans.md).
2020

2121
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
22+
2223
>[!NOTE]
23-
>The Microsoft Sentinel data lake is currently in Public Preview.
24+
>The Microsoft Sentinel data lake is currently in preview. See [Supplemental Terms of Use for Microsoft Azure Previews](/support/legal/preview-supplemental-terms) for additional legal terms that apply to Azure features that are in preview or otherwise not yet released into general availability.
2425
2526
## Storage access logs for cloud providers
2627

articles/sentinel/whats-new.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,8 +22,7 @@ The listed features were released in the last six months. For information about
2222

2323
### Microsoft Sentinel data lake
2424

25-
Microsoft is enhancing its industry-leading SIEM solution, Microsoft Sentinel, with the introduction of a modern data lake—purpose - built to streamline data management, reduce costs, and accelerate AI adoption for security operations teams.
26-
The new Microsoft Sentinel data lake offers cost-effective, long-term storage, eliminating the need to choose between affordability and robust security. Security teams gain deeper visibility and faster incident resolution, all within the familiar Sentinel experience, enriched through seamless integration with advanced data analytics tools.
25+
Microsoft Sentinel is now enhanced with a modern data lake, purpose-built to streamline data management, reduce costs, and accelerate AI adoption for security operations teams. The new Microsoft Sentinel data lake offers cost-effective, long-term storage, eliminating the need to choose between affordability and robust security. Security teams gain deeper visibility and faster incident resolution, all within the familiar Sentinel experience, enriched through seamless integration with advanced data analytics tools.
2726

2827
Key benefits of the Microsoft Sentinel data lake include:
2928
+ Single, open-format data copy for efficient and cost-effective storage

0 commit comments

Comments
 (0)