{"id":4964,"date":"2023-12-11T14:24:19","date_gmt":"2023-12-11T22:24:19","guid":{"rendered":"https:\/\/SUMMALAI.COM\/?p=4964"},"modified":"2023-12-11T14:24:20","modified_gmt":"2023-12-11T22:24:20","slug":"how-to-enable-microsoft-sentinel","status":"publish","type":"post","link":"https:\/\/SUMMALAI.COM\/?p=4964","title":{"rendered":"How to Enable Microsoft Sentinel"},"content":{"rendered":"\n<p>To get started, add Microsoft Sentinel to an existing workspace or create a new one.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Sign in to the&nbsp;<a href=\"https:\/\/portal.azure.com\/\">Azure portal<\/a>.<\/li><li>Search for and select&nbsp;<strong>Microsoft Sentinel<\/strong>.<img decoding=\"async\" src=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/media\/quickstart-onboard\/search-product.png\" alt=\"Screenshot of searching for a service while enabling Microsoft Sentinel.\"><\/li><li>Select&nbsp;<strong>Add<\/strong>.<\/li><li>Select the workspace you want to use or create a new one. You can run Microsoft Sentinel on more than one workspace, but the data is isolated to a single workspace.<img decoding=\"async\" src=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/media\/quickstart-onboard\/choose-workspace.png\" alt=\"Screenshot of choosing a workspace while enabling Microsoft Sentinel.\"><ul><li>The default workspaces created by Microsoft Defender for Cloud aren&#8217;t shown in the list. You can&#8217;t install Microsoft Sentinel on these workspaces.<\/li><li>Once deployed on a workspace, Microsoft Sentinel&nbsp;<strong>doesn&#8217;t currently support<\/strong>&nbsp;moving that workspace to another resource group or subscription.<\/li><\/ul><\/li><li>Select&nbsp;<strong>Add Microsoft Sentinel<\/strong>.<\/li><\/ol>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard#install-a-solution-from-the-content-hub\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"install-a-solution-from-the-content-hub\">Install a solution from the content hub<\/h2>\n\n\n\n<p>The content hub in Microsoft Sentinel is the centralized location to discover and manage out-of-the-box content including data connectors. For this quickstart, install the solution for Azure Activity.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>In Microsoft Sentinel, select&nbsp;<strong>Content hub<\/strong>.<\/li><li>Find and select the&nbsp;<strong>Azure Activity<\/strong>&nbsp;solution.<img decoding=\"async\" src=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/media\/quickstart-onboard\/content-hub-azure-activity.png\" alt=\"Screenshot of the content hub with the solution for Azure Activity selected.\"><\/li><li>On the toolbar at the top of the page, select&nbsp;<img decoding=\"async\" src=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/media\/quickstart-onboard\/install-update-button.png\">&nbsp;<strong>Install\/Update<\/strong>.<\/li><\/ol>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard#set-up-the-data-connector\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"set-up-the-data-connector\">Set up the data connector<\/h2>\n\n\n\n<p>Microsoft Sentinel ingests data from services and apps by connecting to the service and forwarding the events and logs to Microsoft Sentinel. For this quickstart, install the data connector to forward data for Azure Activity to Microsoft Sentinel.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>In Microsoft Sentinel, select&nbsp;<strong>Data connectors<\/strong>.<\/li><li>Search for and select the&nbsp;<strong>Azure Activity<\/strong>&nbsp;data connector.<\/li><li>In the details pane for the connector, select&nbsp;<strong>Open connector page<\/strong>.<\/li><li>Review the instructions to configure the connector.<\/li><li>Select&nbsp;<strong>Launch Azure Policy Assignment Wizard<\/strong>.<\/li><li>On the&nbsp;<strong>Basics<\/strong>&nbsp;tab, set the&nbsp;<strong>Scope<\/strong>&nbsp;to the subscription and resource group that has activity to send to Microsoft Sentinel. For example, select the subscription that contains your Microsoft Sentinel instance.<\/li><li>Select the&nbsp;<strong>Parameters<\/strong>&nbsp;tab.<\/li><li>Set the&nbsp;<strong>Primary Log Analytics workspace<\/strong>. This should be the workspace where Microsoft Sentinel is installed.<\/li><li>Select&nbsp;<strong>Review + create<\/strong>&nbsp;and&nbsp;<strong>Create<\/strong>.<\/li><\/ol>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard#generate-activity-data\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"generate-activity-data\">Generate activity data<\/h2>\n\n\n\n<p>Let&#8217;s generate some activity data by enabling a rule that was included in the Azure Activity solution for Microsoft Sentinel. This step also shows you how to manage content in the content hub.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>In Microsoft Sentinel, select&nbsp;<strong>Content hub<\/strong>.<\/li><li>Find and select the&nbsp;<strong>Azure Activity<\/strong>&nbsp;solution.<\/li><li>From the right-hand side pane, select&nbsp;<strong>Manage<\/strong>.<\/li><li>Find and select the rule template&nbsp;<strong>Suspicious Resource deployment<\/strong>.<\/li><li>Select&nbsp;<strong>Configuration<\/strong>.<\/li><li>Select the rule and&nbsp;<strong>Create rule<\/strong>.<\/li><li>On the&nbsp;<strong>General<\/strong>&nbsp;tab, change the&nbsp;<strong>Status<\/strong>&nbsp;to enabled. Leave the rest of the default values.<\/li><li>Accept the defaults on the other tabs.<\/li><li>On the&nbsp;<strong>Review and create<\/strong>&nbsp;tab, select&nbsp;<strong>Create<\/strong>.<\/li><\/ol>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard#view-data-ingested-into-microsoft-sentinel\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"view-data-ingested-into-microsoft-sentinel\">View data ingested into Microsoft Sentinel<\/h2>\n\n\n\n<p>Now that you&#8217;ve enabled the Azure Activity data connector and generated some activity data let&#8217;s view the activity data added to the workspace.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>In Microsoft Sentinel, select&nbsp;<strong>Data connectors<\/strong>.<\/li><li>Search for and select the&nbsp;<strong>Azure Activity<\/strong>&nbsp;data connector.<\/li><li>In the details pane for the connector, select&nbsp;<strong>Open connector page<\/strong>.<\/li><li>Review the&nbsp;<strong>Status<\/strong>&nbsp;of the data connector. It should be&nbsp;<strong>Connected<\/strong>.<img decoding=\"async\" src=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/media\/quickstart-onboard\/azure-activity-connected-status.png\" alt=\"Screenshot of data connector for Azure Activity with the status showing as connected.\"><\/li><li>In the left-hand side pane above the chart, select&nbsp;<strong>Go to log analytics<\/strong>.<\/li><li>On the top of the pane, next to the&nbsp;<strong>New query 1<\/strong>&nbsp;tab, select the&nbsp;<strong>+<\/strong>&nbsp;to add a new query tab.<\/li><li>In the query pane, run the following query to view the activity date ingested into the workspace.KustoCopy<code> AzureActivity <\/code><img decoding=\"async\" src=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/media\/quickstart-onboard\/azure-activity-logs-query.png\" alt=\"Screenshot of the log query window with results returned for the Azure Activity query.\"><\/li><\/ol>\n\n\n\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard#next-steps\"><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"next-steps\">Next steps<\/h2>\n\n\n\n<p>In this quickstart, you enabled Microsoft Sentinel and installed a solution from the content hub. Then, you set up a data connector to start ingesting data into Microsoft Sentinel. You also verified that data is being ingested by viewing the data in the workspace.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>To visualize the data you&#8217;ve collected by using the dashboards and workbooks, see\u00a0<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/get-visibility\">Visualize collected data<\/a>.<\/li><li>To detect threats by using analytics rules, see\u00a0<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/tutorial-log4j-detection\">Tutorial: Detect threats by using analytics rules in Microsoft Sentinel<\/a>.<\/li><\/ul>\n\n\n\n<p>Ref: <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard\">Quickstart: Onboard in Microsoft Sentinel | Microsoft Learn<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>To get started, add Microsoft Sentinel to an existing workspace or create a new one. Sign in to the&nbsp;Azure portal. Search for and select&nbsp;Microsoft Sentinel. Select&nbsp;Add. Select the workspace you want to use or create a new one. You can run Microsoft Sentinel on more than one workspace, but the data is isolated to a <a class=\"read-more\" href=\"https:\/\/SUMMALAI.COM\/?p=4964\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1249,1526,10],"tags":[1727],"class_list":["post-4964","post","type-post","status-publish","format-standard","hentry","category-azure-microsoft","category-microsoft-defender","category-microsoft","tag-enable-microsoft-sentinel"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4964"}],"version-history":[{"count":1,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4964\/revisions"}],"predecessor-version":[{"id":4965,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4964\/revisions\/4965"}],"wp:attachment":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}