![Blue Security artwork](https://is1-ssl.mzstatic.com/image/thumb/Podcasts114/v4/5d/7e/d0/5d7ed0e1-32bd-15ac-298c-1991d7709c8f/mza_1468887417307528604.jpg/100x100bb.jpg)
Microsoft Sentinel Deep-Dive with Henrik Wojcik
Blue Security
English - February 13, 2024 13:00 - 48 minutes - 47.6 MB - ★★★★★ - 3 ratingsTechnology Homepage Download Apple Podcasts Google Podcasts Overcast Castro Pocket Casts RSS feed
Summary
In this episode, Henrik Wojcik, a Microsoft MVP, joins the hosts to discuss Microsoft Sentinel and provide a deep dive into its deployment and usage. They cover topics such as data residency and compliance considerations, separating operational logs and security logs, connectors for data ingestion, analytics rules and alert fatigue, scheduled queries and user and entity behavior analytics (UEBA), playbooks and automation, workbooks and data visualization, and advanced hunting with KQL queries.
Takeaways
Consider data residency and compliance requirements when deploying Microsoft Sentinel.
Separate operational logs and security logs to optimize cost and focus on relevant data.
Use connectors to ingest data from various sources into Microsoft Sentinel.
Tune analytics rules to avoid alert fatigue and focus on valuable alerts.
Utilize scheduled queries and UEBA to identify suspicious behavior and automate investigations.
Leverage playbooks and automation to streamline incident response and reduce manual effort.
Create workbooks for data visualization and customize them to display relevant information.
Explore advanced hunting with KQL queries to proactively search for threats and investigate incidents.
-------------------------------------------
Youtube Video Link: https://youtu.be/n9dDfmX-A9Q
-------------------------------------------
Documentation:
https://learn.microsoft.com/en-us/azure/sentinel/data-connectors-reference
https://learn.microsoft.com/en-us/azure/sentinel/create-custom-connector
Henrik Wojcik:
https://www.linkedin.com/in/henrikfrandswojcik/
https://twitter.com/henrikwojcik
----------------------
Contact Us:
Threads: https://www.threads.net/@bluesecuritypodcast
-------------------------------------------
Andy Jaw
-------------------------------------------
Adam Brewer
Email: [email protected]