Skip to content

Commit eb6270a

Browse files
Merge pull request #278337 from cwatson-cat/6-14-24-wb-upds-2
Track migration - minor upds/edits
2 parents 639ac28 + 4fd4200 commit eb6270a

File tree

1 file changed

+34
-22
lines changed

1 file changed

+34
-22
lines changed

articles/sentinel/migration-track.md

Lines changed: 34 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,18 @@ description: Learn how to track your migration with a workbook, how to customize
44
author: cwatson
55
ms.author: cwatson
66
ms.topic: how-to
7-
ms.date: 06/06/2024
7+
ms.date: 06/14/2024
8+
appliesto:
9+
- Microsoft Sentinel in the Azure portal and the Microsoft Defender portal
10+
ms.collection: usx-security
811
---
912

1013
# Track your Microsoft Sentinel migration with a workbook
1114

12-
As your organization's Security Operations Center (SOC) handles growing amounts of data, it's essential to plan and monitor your deployment status. While you can track your migration process using generic tools such as Microsoft Project, Microsoft Excel, Teams, or Azure DevOps, these tools aren’t specific to SIEM migration tracking. To help you with tracking, we provide a dedicated workbook in Microsoft Sentinel named **Microsoft Sentinel Deployment and Migration**.
15+
As your organization's security operations center (SOC) handles growing amounts of data, it's essential to plan and monitor your deployment status. While you can track your migration process using generic tools such as Microsoft Project, Microsoft Excel, Microsoft Teams, or Azure DevOps, these tools aren’t specific to security information and event management (SIEM) migration tracking. To help you to track, we provide a dedicated workbook in Microsoft Sentinel named **Microsoft Sentinel Deployment and Migration**.
1316

1417
The workbook helps you to:
18+
1519
- Visualize migration progress
1620
- Deploy and track data sources
1721
- Deploy and monitor analytics rules and incidents
@@ -23,14 +27,18 @@ This article describes how to track your migration with the **Microsoft Sentinel
2327

2428
## Deploy the workbook content and view the workbook
2529

30+
To get the workbook, first install the standalone item from the **Content hub** in Microsoft Sentinel.
31+
2632
1. In the Microsoft Sentinel **Content hub**, filter the content listed by **Content type** = **Workbooks**, and then enter *migration* in the search bar.
2733

2834
1. From the search results, select the **Microsoft Sentinel Deployment and Migration** workbook and then select **Install**. Microsoft Sentinel deploys the workbook and saves the workbook in your environment.
29-
30-
1. To view the workbook, select **Open saved workbook**.
35+
1. In Microsoft Sentinel, under **Threat management**, select **Workbooks** > **Templates**.
36+
1. Select the **Microsoft Sentinel Deployment and Migration** workbook and **View template**.
3137

3238
## Deploy the watchlist
3339

40+
The next step is to deploy the related watchlist from the Microsoft Sentinel GitHub repository.
41+
3442
1. In the [Microsoft Sentinel GitHub repository](https://github.com/Azure/Azure-Sentinel/tree/master/Watchlists), select the **DeploymentandMigration** folder, and select **Deploy to Azure** to begin the template deployment in Azure.
3543
1. Provide the Microsoft Sentinel resource group and workspace name.
3644
:::image type="content" source="media/migration-track/migration-track-azure-deployment.png" alt-text="Screenshot of deploying the watchlist to Azure.":::
@@ -39,19 +47,20 @@ This article describes how to track your migration with the **Microsoft Sentinel
3947

4048
## Update the watchlist with deployment and migration actions
4149

42-
This step is crucial to the tracking setup process. If you skip this step, the workbook won't reflect the items for tracking.
50+
This step is crucial to the tracking setup process. If you skip this step, the workbook doesn't reflect the items for tracking.
4351

4452
To update the watchlist with deployment and migration actions:
4553

46-
1. In the Azure portal, select Microsoft Sentinel and then select **Watchlist**.
47-
1. Locate the watchlist with the **Deployment** alias.
48-
1. Select the watchlist, and then select **Update watchlist > edit watchlist items** on the bottom right.
49-
:::image type="content" source="media/migration-track/migration-track-update-watchlist.png" alt-text="Screenshot of updating watchlist items with deployment and migration actions." lightbox="media/migration-track/migration-track-update-watchlist.png":::
50-
1. Provide the information for the actions needed for the deployment and migration, and select **Save**.
54+
1. In the Azure or Microsoft Defender portal, select Microsoft Sentinel and then select **Watchlist**.
55+
1. Select the watchlist with the **Deployment** alias.
56+
1. Then select **Update watchlist > edit watchlist items**.
57+
1. Provide the information for the actions needed for the deployment and migration.
58+
:::image type="content" source="media/migration-track/migration-track-update-watchlist.png" alt-text="Screenshot of updating watchlist items with deployment and migration actions." lightbox="media/migration-track/migration-track-update-watchlist.png":::
59+
1. Select **Save**.
5160

5261
You can now view the watchlist within the migration tracker workbook. Learn how to [manage watchlists](watchlists-manage.md).
5362

54-
In addition, your team might update or complete tasks during the deployment process. To address these changes, you can update existing actions or add new actions as you identify new use cases or set new requirements. To update or add actions, edit the **Deployment** watchlist that you [deployed previously](#deploy-the-watchlist). To simplify the process, select **Edit Deployment Watchlist** on the bottom left to open the watchlist directly from the workbook.
63+
In addition, your team might update or complete tasks during the deployment process. To address these changes, update existing actions or add new actions as you identify new use cases or set new requirements. To update or add actions, edit the **Deployment** watchlist that you deployed. To simplify the process, in the workbook, select **Edit Deployment Watchlist** to open the watchlist directly from the workbook.
5564

5665
## View deployment status
5766

@@ -68,6 +77,7 @@ To quickly view the deployment progress, in the **Microsoft Sentinel Deployment
6877
## Deploy and monitor data connectors
6978

7079
To monitor deployed resources and deploy new connectors, in the **Microsoft Sentinel Deployment and Migration** workbook, select **Data Connectors > Monitor**. The **Monitor** view lists:
80+
7181
- Current ingestion trends
7282
- Tables ingesting data
7383
- How much data each table is reporting
@@ -81,30 +91,31 @@ To monitor deployed resources and deploy new connectors, in the **Microsoft Sent
8191
:::image type="content" source="media/migration-track/migration-track-data-connectors.png" alt-text="Screenshot of the workbook's Data Connectors tab Monitor view." lightbox="media/migration-track/migration-track-data-connectors.png":::
8292

8393
To configure a data connector:
94+
8495
1. Select the **Configure** view.
8596
1. Select the button with the name of the connector you want to configure.
8697
1. Configure the connector in the connector status screen that opens. If you can't find a connector you need, select the connector name to open the connector gallery or solution gallery.
8798
:::image type="content" source="media/migration-track/migration-track-configure-data-connectors.png" alt-text="Screenshot of the workbook's Configure view.":::
8899

89100
## Deploy and monitor analytics and incidents
90101

91-
Once the data is reported in the workspace, you can now configure and monitor analytics rules. In the **Microsoft Sentinel Deployment and Migration** workbook, select **Analytics** to view all deployed rule templates and lists. This view indicates which rules are currently in use and how often the rules generate incidents.
102+
When the data is reported in the workspace, configure and monitor analytics rules. In the **Microsoft Sentinel Deployment and Migration** workbook, select the **Analytics** tab to view all deployed rule templates and lists. This view indicates which rules are currently in use and how often the rules generate incidents.
92103

93104
:::image type="content" source="media/migration-track/migration-track-analytics.png" alt-text="Screenshot of the workbook's Analytics tab." lightbox="media/migration-track/migration-track-analytics.png":::
94105

95106
If you need more coverage, select **Review MITRE coverage** below the table on the left. Use this option to define which areas receive more coverage and which rules are deployed, at any stage of the migration project.
96107

97108
:::image type="content" source="media/migration-track/migration-track-mitre.png" alt-text="Screenshot of the workbook's MITRE Coverage view." lightbox="media/migration-track/migration-track-mitre.png":::
98109

99-
Once the desired analytics rules are deployed and the Defender product connector is configured to send the alerts, you can monitor incident creation and frequency under **Deployment > Summary of progress**. This area displays metrics regarding alert generation by product, title, and classification, to indicate the health of the SOC and which alerts require the most attention. If alerts are generating too much volume, return to the **Analytics** tab to modify the logic.
110+
When you deploy the analytics rules and the Defender product connector is configured to send the alerts, monitor incident creation and frequency under **Deployment > Summary of progress**. This area displays metrics regarding alert generation by product, title, and classification, to indicate the health of the SOC and which alerts require the most attention. If alerts are generating too much volume, return to the **Analytics** tab to modify the logic.
100111

101112
:::image type="content" source="media/migration-track/migration-track-analytics-monitor.png" alt-text="Screenshot of the summary of progress under the workbook's Analytics tab." lightbox="media/migration-track/migration-track-analytics-monitor.png":::
102113

103114
## Deploy and utilize workbooks
104115

105-
To visualize information regarding the data ingestion and detections that Microsoft Sentinel performs, in the **Microsoft Sentinel Deployment and Migration** workbook, select **Workbooks**. Similar to the **Data Connectors** tab, you can use the **Monitor** and **Configure** views to view monitoring and configuration information.
116+
To visualize information regarding the data ingestion and detections that Microsoft Sentinel performs, in the **Microsoft Sentinel Deployment and Migration** workbook, select **Workbooks**. Similar to the **Data Connectors** tab, use the **Monitor** and **Configure** views to view monitoring and configuration information.
106117

107-
Here are some useful tasks you can perform in the **Workbooks** tab:
118+
Here are some useful tasks to do in the **Workbooks** tab:
108119

109120
- To view a list of all workbooks in the environment and how many workbooks are deployed, select **Monitor**.
110121
- To view a specific workbook within the **Microsoft Sentinel Deployment and Migration** workbook, select a workbook and then select **Open Selected Workbook**.
@@ -117,7 +128,7 @@ Here are some useful tasks you can perform in the **Workbooks** tab:
117128

118129
## Deploy and monitor playbooks and automation rules
119130

120-
Once you configure data ingestion, detections, and visualizations, you can now look into automation. In the **Microsoft Sentinel Deployment and Migration** workbook, select **Automation** to view deployed playbooks, and to see which playbooks are currently connected to an automation rule. If automation rules exist, the workbook highlights the following information regarding each rule:
131+
When you configure data ingestion, detections, and visualizations, you can now look into automation. In the **Microsoft Sentinel Deployment and Migration** workbook, select **Automation** to view deployed playbooks, and to see which playbooks are currently connected to an automation rule. If automation rules exist, the workbook highlights the following information regarding each rule:
121132
- Name
122133
- Status
123134
- Action or actions of the rule
@@ -142,7 +153,7 @@ To enable U E B A:
142153
1. Select the data sources you want to use to generate insights.
143154
1. Select **Apply**.
144155

145-
After you enable U E B A, you can monitor and ensure that Microsoft Sentinel is generating U E B A data.
156+
After you enable U E B A, monitor and ensure that Microsoft Sentinel is generating U E B A data.
146157

147158
To customize the timeline:
148159
1. Select **Customize Entity Timeline** above the list of tables.
@@ -153,28 +164,29 @@ Learn more about [U E B A](identify-threats-with-entity-behavior-analytics.md) o
153164

154165
## Configure and manage the data lifecycle
155166

156-
When you deploy or migrate to Microsoft Sentinel, it's essential to manage the usage and lifecycle of the incoming logs. To assist with this, in the **Microsoft Sentinel Deployment and Migration** workbook, select **Data Management** to view and configure table retention and archival.
167+
When you deploy or migrate to Microsoft Sentinel, it's essential to manage the usage and lifecycle of the incoming logs. In the **Microsoft Sentinel Deployment and Migration** workbook, select **Data Management** to view and configure table retention and archival.
157168

158169
:::image type="content" source="media/migration-track/migration-track-data-management.png" alt-text="Screenshot of the workbook's Data Management tab." lightbox="media/migration-track/migration-track-data-management.png":::
159170

160-
You can view information regarding:
171+
View information regarding:
161172

162173
- Tables configured for basic log ingestion
163174
- Tables configured for analytics tier ingestion
164175
- Tables configured to be archived
165176
- Tables on the default workspace retention
166177

167178
To modify the existing retention policy for tables:
179+
168180
1. Select the **Default Retention Tables** view.
169-
1. Select the table you want to modify, and select **Update Retention**. You can edit the following information:
181+
1. Select the table you want to modify, and select **Update Retention**. Edit the following information as needed:
170182
- Current retention in the workspace
171183
- Current retention in the archive
172-
- Total number of days the data will live in the environment
184+
- Total number of days the data lives in the environment
173185
1. Edit the **TotalRetention** value to set a new total number of days that the data should exist within the environment.
174186

175187
The **ArchiveRetention** value is calculated by subtracting the **TotalRetention** value from the **InteractiveRetention** value. If you need to adjust the workspace retention, the change doesn't impact tables that include configured archives and data isn't lost. If you edit the **InteractiveRetention** value and the **TotalRetention** value doesn't change, Azure Log Analytics adjusts the archive retention to compensate the change.
176188

177-
If you prefer to make changes in the UI, select **Update Retention in UI** to open the relevant blade.
189+
If you prefer to make changes in the UI, select **Update Retention in UI** to open the relevant page.
178190

179191
Learn about [data lifecycle management](../azure-monitor/logs/data-retention-archive.md).
180192

0 commit comments

Comments
 (0)