Skip to content

Commit 862891c

Browse files
Merge pull request #50795 from KenMAG/main
Cleaned up markdown and improved Acrolynx scores.
2 parents aa33372 + a391678 commit 862891c

10 files changed

+41
-55
lines changed

learn-pr/wwl-sci/manage-content-microsoft-sentinel/1-introduction.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@ title: Introduction
44
metadata:
55
title: Introduction
66
description: "Introduction"
7-
ms.date: 11/22/2022
8-
author: wwlpublish
7+
ms.date: 06/04/2025
8+
author: KenMAG
99
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false

learn-pr/wwl-sci/manage-content-microsoft-sentinel/2-use-solutions-from-content-hub.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@ title: Use solutions from the content hub
44
metadata:
55
title: Use solutions from the content hub
66
description: "Use solutions from the content hub"
7-
ms.date: 11/22/2022
8-
author: wwlpublish
7+
ms.date: 06/04/2025
8+
author: KenMAG
99
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false

learn-pr/wwl-sci/manage-content-microsoft-sentinel/3-use-repositories-for-deployment.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@ title: Use repositories for deployment
44
metadata:
55
title: Use repositories for deployment
66
description: "Use repositories for deployment"
7-
ms.date: 11/22/2022
8-
author: wwlpublish
7+
ms.date: 06/04/2025
8+
author: KenMAG
99
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false

learn-pr/wwl-sci/manage-content-microsoft-sentinel/4-knowledge-check.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,13 @@ quiz:
2020
choices:
2121
- content: "Azure DevOps only"
2222
isCorrect: false
23-
explanation: "Incorrect. Both repository types are supported."
23+
explanation: "Incorrect. Both repository types are supported."
2424
- content: "GitHub only"
2525
isCorrect: false
26-
explanation: "Incorrect. Both repository types are supported."
26+
explanation: "Incorrect. Both repository types are supported."
2727
- content: "GitHub and Azure DevOps"
2828
isCorrect: true
29-
explanation: "Correct. Both repository types are supported."
29+
explanation: "Correct. Both repository types are supported."
3030
- content: "Which content type is supported by content hub solutions?"
3131
choices:
3232
- content: "Advanced Multistage Attack Detection Fusion Rule"
@@ -37,15 +37,15 @@ quiz:
3737
explanation: "Correct. Parsers are supported in a content hub solution."
3838
- content: "Search job"
3939
isCorrect: false
40-
explanation: "Incorrect. Parsers are supported in a content hub solution."
40+
explanation: "Incorrect. Parsers are supported in a content hub solution."
4141
- content: "What is the maximum number of repository connections allowed for each Microsoft Sentinel workspace?"
4242
choices:
43-
- content: "3"
43+
- content: "Three"
4444
isCorrect: false
4545
explanation: "Incorrect. Five is the maximum connections for each workspace."
46-
- content: "5"
46+
- content: "Five"
4747
isCorrect: true
48-
explanation: "Correct. Five is the maximum connections for each workspace."
49-
- content: "10"
48+
explanation: "Correct. Five is the maximum connections for each workspace."
49+
- content: "Ten"
5050
isCorrect: false
5151
explanation: "Incorrect. Five is the maximum connections for each workspace."

learn-pr/wwl-sci/manage-content-microsoft-sentinel/5-summary-resources.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@ title: Summary and resources
44
metadata:
55
title: Summary and resources
66
description: "Summary and resources"
7-
ms.date: 11/22/2022
8-
author: wwlpublish
7+
ms.date: 06/04/2025
8+
author: KenMAG
99
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false

learn-pr/wwl-sci/manage-content-microsoft-sentinel/includes/1-introduction.md

Lines changed: 4 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -11,28 +11,17 @@ Content in Microsoft Sentinel includes any of the following types:
1111
- **Watchlists** support the ingestion of specific data for enhanced threat detection and reduced alert fatigue
1212
- **Playbooks** and Azure Logic Apps custom connectors provide features for automated investigations, remediations, and response scenarios in Microsoft Sentinel
1313

14-
1514
To maintain **content** in for Microsoft Sentinel use:
15+
1616
- **Content hub**: - Microsoft Sentinel **solutions** are packages of Microsoft Sentinel content or Microsoft Sentinel API integrations, which fulfill an end-to-end product, domain, or industry vertical scenario in Microsoft Sentinel.
1717
- **Repositories**: - Repositories help you automate the deployment and management of your Microsoft Sentinel content through central repositories.
18-
- **Community**: Onboard community content on-demand to enable your scenarios. The GitHub repo at https://github.com/Azure/Azure-Sentinel contains content by Microsoft and the community that is tested and available for you to implement in your Sentinel workspace.
19-
20-
21-
You're a Security Operations Analyst working at a company that implemented Microsoft Sentinel. You need to install connectors and analytical rules from a vendor. You also have created a library of hunting queries that need to be maintained across multiple environments.
18+
- **Community**: Onboard community content on-demand to enable your scenarios. The GitHub repo at <https://github.com/Azure/Azure-Sentinel> contains content by Microsoft and the community that is tested and available for you to implement in your Sentinel workspace.
2219

20+
You're a Security Operations Analyst working at a company that implemented Microsoft Sentinel. You need to install connectors and analytical rules from a vendor. You also created a library of hunting queries that need to be maintained across multiple environments.
2321

24-
By the end of this module, you'll be able to manage *content* in Microsoft Sentinel.
22+
By the end of this module, you are able to manage *content* in Microsoft Sentinel.
2523

2624
After completing this module, you'll be able to:
2725

2826
- Install a content hub solution in Microsoft Sentinel
2927
- Connect a GitHub repository to Microsoft Sentinel
30-
31-
32-
33-
34-
35-
36-
37-
38-

learn-pr/wwl-sci/manage-content-microsoft-sentinel/includes/2-use-solutions-from-content-hub.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ Manage updates for out-of-the-box content via the Microsoft Sentinel Content hub
88

99
Customize out-of-the-box content for your own needs, or create custom content, including analytics rules, hunting queries, notebooks, workbooks, and more. Manage your custom content directly in your Microsoft Sentinel workspace, via the Microsoft Sentinel API, or in your own source control repository, via the Microsoft Sentinel Repositories page.
1010

11-
1211
## Solutions
12+
1313
Microsoft Sentinel solutions are packaged content or integrations that deliver end-to-end product value for one or more domain or vertical scenarios.
1414

1515
The solutions experience is powered by Azure Marketplace for solutions’ discoverability and deployment.
@@ -37,12 +37,12 @@ Use the Content hub to centrally discover and deploy solutions and out-of-the-bo
3737

3838
For example, in the Cisco Umbrella solution shows a category of Security - Others, and that this solution includes 10 analytics rules, 11 hunting queries, a parser, three playbooks, and more.
3939

40+
## Install or update a solution
4041

41-
### Install or update a solution
4242
- In the content hub, select a solution to view more information on the right. Then select Install, or Update, if you need updates. For example:
4343

4444
- On the solution details page, select Create or Update to start the solution wizard. On the wizard's Basics tab, enter the subscription, resource group, and workspace to which you want to deploy the solution.
4545

4646
- Select Next to cycle through the remaining tabs (corresponding to the components included in the solution), where you can learn about, and in some cases configure, each of the content components.
4747

48-
- Finally, in the Review + create tab, wait for the Validation Passed message, then select Create or Update to deploy the solution. You can also select the Download a template for automation link to deploy the solution as code.
48+
- Finally, in the Review + create tab, wait for the Validation Passed message, then select Create or Update to deploy the solution. You can also select the Download a template for automation link to deploy the solution as code.

learn-pr/wwl-sci/manage-content-microsoft-sentinel/includes/3-use-repositories-for-deployment.md

Lines changed: 13 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
When creating custom content, you can store and manage it in your own Microsoft Sentinel workspaces, or an external source control repository, including GitHub and Azure DevOps repositories. Managing your content in an external repository allows you to make updates to that content outside of Microsoft Sentinel, and have it automatically deployed to your workspaces.
22

3-
43
## Prerequisites and scope
4+
55
Before connecting your Microsoft Sentinel workspace to an external source control repository, make sure that you have:
66

77
- Access to a GitHub or Azure DevOps repository, with any custom content files you want to deploy to your workspaces, in relevant Azure Resource Manager (ARM) templates.
@@ -11,11 +11,13 @@ Before connecting your Microsoft Sentinel workspace to an external source contro
1111
- An Owner role in the resource group that contains your Microsoft Sentinel workspace. This role is required to create the connection between Microsoft Sentinel and your source control repository. If you're unable to use the Owner role in your environment, you can instead use the combination of User Access Administrator and Sentinel Contributor roles to create the connection.
1212

1313
## Maximum connections and deployments
14+
1415
Each Microsoft Sentinel workspace is currently limited to five connections.
1516

1617
Each Azure resource group is limited to 800 deployments in its deployment history. If you have a high volume of ARM template deployments in your resource group(s), you may see a Deployment QuotaExceeded error.
1718

1819
## Validate your content
20+
1921
Deploying content to Microsoft Sentinel via a repository connection doesn't validate that content other than verifying that the data is in the correct ARM template format.
2022

2123
We recommend that you validate your content templates using your regular validation process. You can use the Microsoft Sentinel GitHub validation process and tools to set up your own validation process.
@@ -42,24 +44,23 @@ To create your connection:
4244

4345
- Enter your GitHub credentials when prompted.
4446

45-
The first time you add a connection, you'll see a new browser window or tab, prompting you to authorize the connection to Microsoft Sentinel. If you're already logged into your GitHub account on the same browser, your GitHub credentials will be auto-populated.
47+
The first time you add a connection, you see a new browser window or tab, prompting you to authorize the connection to Microsoft Sentinel. If you're already logged into your GitHub account on the same browser, your GitHub credentials are auto-populated.
4648

4749
- A Repository area now shows on the Create a new connection page, where you can select an existing repository to connect to. Select your repository from the list, and then select Add repository.
4850

49-
The first time you connect to a specific repository, you'll see a new browser window or tab, prompting you to install the Azure-Sentinel app on your repository. If you have multiple repositories, select the ones where you want to install the Azure-Sentinel app, and install it.
51+
The first time you connect to a specific repository, you see a new browser window or tab, prompting you to install the Azure-Sentinel app on your repository. If you have multiple repositories, select the ones where you want to install the Azure-Sentinel app, and install it.
5052

51-
You'll be directed to GitHub to continue the app installation.
53+
You are directed to GitHub to continue the app installation.
5254

5355
- After the Azure-Sentinel app is installed in your repository, the Branch dropdown in the Create a new connection page is populated with your branches. Select the branch you want to connect to your Microsoft Sentinel workspace.
5456

55-
- From the Content Types dropdown, select the type of content you'll be deploying.
56-
57-
- Both parsers and hunting queries use the Saved Searches API to deploy content to Microsoft Sentinel. If you select one of these content types, and also have content of the other type in your branch, both content types are deployed.
57+
- From the Content Types dropdown, select the type of content you are deploying.
5858

59-
- For all other content types, selecting a content type in the Create a new connection pane deploys only that content to Microsoft Sentinel. Content of other types isn't deployed.
59+
- Both parsers and hunting queries use the Saved Searches API to deploy content to Microsoft Sentinel. If you select one of these content types, and also have content of the other type in your branch, both content types are deployed.
6060

61-
- Select Create to create your connection.
61+
- For all other content types, selecting a content type in the Create a new connection pane deploys only that content to Microsoft Sentinel. Content of other types isn't deployed.
6262

63+
- Select Create to create your connection.
6364

6465
After the connection is created, a new workflow or pipeline is generated in your repository, and the content stored in your repository is deployed to your Microsoft Sentinel workspace.
6566

@@ -71,15 +72,12 @@ The deployment time may vary depending on the volume of content that you're depl
7172

7273
- In Microsoft Sentinel, from the dropdown lists that appear, select your Organization, Project, Repository, Branch, and Content Types.
7374

74-
- Both parsers and hunting queries use the Saved Searches API to deploy content to Microsoft Sentinel. If you select one of these content types, and also have content of the other type in your branch, both content types are deployed.
75+
- Both parsers and hunting queries use the Saved Searches API to deploy content to Microsoft Sentinel. If you select one of these content types, and also have content of the other type in your branch, both content types are deployed.
7576

76-
- For all other content types, selecting a content type in the Create a new connection pane deploys only that content to Microsoft Sentinel. Content of other types isn't deployed.
77+
- For all other content types, selecting a content type in the Create a new connection pane deploys only that content to Microsoft Sentinel. Content of other types isn't deployed.
7778

7879
- Select Create to create your connection. For example:
7980

80-
81-
82-
8381
After the connection is created, a new workflow or pipeline is generated in your repository, and the content stored in your repository is deployed to your Microsoft Sentinel workspace.
8482

85-
The deployment time may vary depending on the volume of content that you're deploying.
83+
The deployment time may vary depending on the volume of content that you're deploying.
Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,15 @@
11

2-
By the end of this module, you'll be able to manage *content* in Microsoft Sentinel.
2+
By the end of this module, you're able to manage *content* in Microsoft Sentinel.
33

44
You should now be able to:
55

66
- Install a content hub solution in Microsoft Sentinel
77
- Connect a GitHub repository to Microsoft Sentinel
88

9-
109
## Learn more
1110

1211
You can learn more by reviewing the following.
1312

1413
[Become a Microsoft Sentinel Ninja](https://techcommunity.microsoft.com/t5/azure-sentinel/become-an-azure-sentinel-ninja-the-complete-level-400-training/ba-p/1246310?azure-portal=true)
1514

16-
[Microsoft Tech Community Security Webinars](https://techcommunity.microsoft.com/t5/microsoft-security-and/security-community-webinars/ba-p/927888?azure-portal=true)
15+
[Microsoft Tech Community Security Webinars](https://techcommunity.microsoft.com/t5/microsoft-security-and/security-community-webinars/ba-p/927888?azure-portal=true)

learn-pr/wwl-sci/manage-content-microsoft-sentinel/index.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,13 +3,13 @@ uid: learn.wwl.manage-content-microsoft-sentinel
33
metadata:
44
title: Manage content in Microsoft Sentinel
55
description: "Manage content in Microsoft Sentinel"
6-
ms.date: 11/22/2022
7-
author: wwlpublish
6+
ms.date: 06/04/2025
7+
author: KenMAG
88
ms.author: kelawson
99
ms.topic: module
1010
ms.service: microsoft-sentinel
1111
title: Manage content in Microsoft Sentinel
12-
summary: By the end of this module, you'll be able to manage _content_ in Microsoft Sentinel.
12+
summary: By the end of this module, you're able to manage _content_ in Microsoft Sentinel.
1313
abstract: |
1414
After completing this module, you'll be able to:
1515
* Install a content hub solution in Microsoft Sentinel

0 commit comments

Comments
 (0)