| Add advanced OR condition groups to Sentinel automation rules |
https://learn.microsoft.com/en-us/azure/sentinel/add-advanced-conditions-to-automation-rules |
| Use Microsoft Sentinel audit tables for monitoring |
https://learn.microsoft.com/en-us/azure/sentinel/audit-table-reference |
| Configure Microsoft Sentinel automation rules and conditions |
https://learn.microsoft.com/en-us/azure/sentinel/automation-rule-reference |
| Security content reference for Power Platform and CE |
https://learn.microsoft.com/en-us/azure/sentinel/business-applications/power-platform-solution-security-content |
| Map CEF keys to Sentinel CommonSecurityLog fields |
https://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping |
| Configure Syslog and CEF connectors via Azure Monitor Agent |
https://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-overview |
| Configure Security Events connector for anomalous RDP detection |
https://learn.microsoft.com/en-us/azure/sentinel/configure-connector-login-detection |
| Configure interactive and long-term Sentinel data retention |
https://learn.microsoft.com/en-us/azure/sentinel/configure-data-retention-archive |
| Configure ingestion-time data transformation and custom log ingestion |
https://learn.microsoft.com/en-us/azure/sentinel/configure-data-transformation |
| Configure Fusion multistage attack detection rules |
https://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules |
| Configure AWS service log connector for Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-aws |
| Prepare AWS environment to send logs to Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-aws-configure-environment |
| Configure AWS WAF S3 connector to ingest logs to Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-aws-s3-waf |
| Configure Microsoft Entra ID connector to send logs to Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory |
| Connect Azure Virtual Desktop telemetry to Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-azure-virtual-desktop |
| Configure Sentinel connections to Azure and Microsoft services |
https://learn.microsoft.com/en-us/azure/sentinel/connect-azure-windows-microsoft-services |
| Configure AMA-based syslog and CEF ingestion to Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog-ama |
| Configure Custom Logs via AMA to ingest text-file logs |
https://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs-ama |
| Connect Microsoft Defender for Cloud alerts to Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-defender-for-cloud |
| Configure AMA connector for Windows DNS log streaming |
https://learn.microsoft.com/en-us/azure/sentinel/connect-dns-ama |
| Configure GCP Pub/Sub connectors to ingest logs into Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-google-cloud-platform |
| Configure Microsoft Defender XDR connector in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender |
| Stream Microsoft Purview Information Protection data to Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-purview |
| Configure API-based data connectors for Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-services-api-based |
| Configure diagnostic settings-based connectors for Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-services-diagnostic-setting-based |
| Configure Windows agent-based data connectors for Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/connect-services-windows-based |
| Create scheduled analytics rules from Sentinel templates |
https://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rule-from-template |
| Create custom scheduled analytics rules in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rules |
| Configure incident creation from alerts in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts |
| Configure Sentinel automation rules for incident response |
https://learn.microsoft.com/en-us/azure/sentinel/create-manage-use-automation-rules |
| Create and manage NRT detection rules in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/create-nrt-rules |
| Create Sentinel incident task lists via automation rules |
https://learn.microsoft.com/en-us/azure/sentinel/create-tasks-automation-rule |
| Customize Sentinel alert names, severity, and tactics |
https://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details |
| Customize activities on Sentinel entity timelines |
https://learn.microsoft.com/en-us/azure/sentinel/customize-entity-activities |
| Configure RestApiPoller connector JSON for Sentinel CCF |
https://learn.microsoft.com/en-us/azure/sentinel/data-connector-connection-rules-reference |
| Reference Sentinel-supported data source schemas |
https://learn.microsoft.com/en-us/azure/sentinel/data-source-schema-reference |
| Configure custom data ingestion and transformation for Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/data-transformation |
| Use asset data tables in Microsoft Sentinel data lake |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/asset-data-tables |
| Create and schedule KQL jobs in Sentinel data lake |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs |
| Configure KQL jobs to promote Sentinel lake data |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs |
| Manage Microsoft Sentinel data lake KQL jobs |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-manage-jobs |
| Configure and run KQL queries and jobs in Sentinel data lake |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries |
| Create and schedule Jupyter notebook jobs in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-jobs |
| Configure connectors and retention for Sentinel data lake tiers |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-connectors |
| Onboard Sentinel data lake from Defender portal |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboard-defender |
| Onboard tenants to Microsoft Sentinel data lake and graph |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboarding |
| Configure and use the Microsoft Sentinel MCP server |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started |
| Use Sentinel MCP tools with Microsoft Foundry AI agents |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-azure-ai-foundry |
| Configure Sentinel MCP tools in Microsoft Copilot Studio |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-copilot-studio |
| Add Sentinel MCP tools to Microsoft Security Copilot |
https://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-security-copilot |
| Configure DNS over AMA connector fields and schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/dns-ama-fields |
| Security content reference for Dynamics 365 F&O |
https://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/dynamics-365-finance-operations-security-content |
| Enable and configure Sentinel UEBA data sources |
https://learn.microsoft.com/en-us/azure/sentinel/enable-entity-behavior-analytics |
| Enable Sentinel auditing and health monitoring and query logs |
https://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring |
| Use Sentinel entity types and identifiers correctly |
https://learn.microsoft.com/en-us/azure/sentinel/entities-reference |
| Configure auditing and health monitoring in Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/health-audit |
| Query and interpret Microsoft Sentinel health tables |
https://learn.microsoft.com/en-us/azure/sentinel/health-table-reference |
| Bulk import threat indicators from files into Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/indicators-bulk-file-import |
| Manage Sentinel analytics rule template versions |
https://learn.microsoft.com/en-us/azure/sentinel/manage-analytics-rule-templates |
| Configure and manage installed Microsoft Sentinel platform solutions |
https://learn.microsoft.com/en-us/azure/sentinel/manage-platform-solutions |
| Configure table retention and tier settings for Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/manage-table-tiers-retention |
| Map analytics rule fields to Sentinel entities |
https://learn.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities |
| Use Purview Information Protection connector record types in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/microsoft-purview-record-types-activities |
| Monitor Sentinel automation rules and playbook health |
https://learn.microsoft.com/en-us/azure/sentinel/monitor-automation-health |
| Monitor Microsoft Sentinel data connector health and ingestion |
https://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health |
| Monitor SAP–Sentinel connection health and alerts |
https://learn.microsoft.com/en-us/azure/sentinel/monitor-sap-system-health |
| Configure near-real-time analytics rules in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/near-real-time-rules |
| Use ASIM parsers in Sentinel KQL queries |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-about-parsers |
| Manage workspace-deployed ASIM parsers in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-about-workspace-parsers |
| Apply ASIM common schema fields in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-common-fields |
| Develop and deploy custom ASIM parsers for Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-develop-parsers |
| Implement ASIM Application Entity schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-application |
| Implement ASIM Device Entity schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-device |
| Implement ASIM User Entity schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-user |
| Manage and customize ASIM parsers in Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers |
| Convert Sentinel content to use ASIM normalized data |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-modify-content |
| Use ASIM Alert Events normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-alert |
| Use ASIM Audit Events normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-audit |
| Use ASIM Authentication normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-authentication |
| Use ASIM DHCP normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dhcp |
| Use ASIM DNS normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dns |
| Use ASIM File Event normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-file-event |
| Use ASIM Network Session normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-network |
| Use ASIM Process Event normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-process-event |
| Use ASIM Registry Event normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-registry-event |
| Use Sentinel user management normalization schema |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-user-management |
| Use legacy Sentinel network normalization schema v0.1 |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-v1 |
| Use ASIM Web Session normalization schema in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-web |
| Configure Sentinel notebooks and MSTICPy basics |
https://learn.microsoft.com/en-us/azure/sentinel/notebook-get-started |
| Apply advanced MSTICPy and notebook settings in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/notebooks-msticpy-advanced |
| Remove Microsoft Sentinel from a Log Analytics workspace |
https://learn.microsoft.com/en-us/azure/sentinel/offboard |
| Integrate Microsoft Purview solution with Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/purview-solution |
| Restore archived Sentinel logs for high-performance queries |
https://learn.microsoft.com/en-us/azure/sentinel/restore |
| Configure SAP HANA audit log collection in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/sap/collect-sap-hana-audit-logs |
| Prepare SAP systems for Sentinel SAP connector |
https://learn.microsoft.com/en-us/azure/sentinel/sap/preparing-sap |
| Review prerequisites for Sentinel SAP solution deployment |
https://learn.microsoft.com/en-us/azure/sentinel/sap/prerequisites-for-deploying-sap-continuous-threat-monitoring |
| Kickstart script parameters for SAP connector deployment |
https://learn.microsoft.com/en-us/azure/sentinel/sap/reference-kickstart |
| Legacy systemconfig.ini settings for Sentinel SAP agent |
https://learn.microsoft.com/en-us/azure/sentinel/sap/reference-systemconfig |
| systemconfig.json settings for Sentinel SAP agent |
https://learn.microsoft.com/en-us/azure/sentinel/sap/reference-systemconfig-json |
| Update script parameters for Sentinel SAP connector |
https://learn.microsoft.com/en-us/azure/sentinel/sap/reference-update |
| Use SAP Security Audit Controls workbook in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-audit-controls-workbook |
| Use SAP Security Audit log workbook in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-audit-log-workbook |
| Security content reference for Sentinel SAP BTP solution |
https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-btp-security-content |
| Function reference for Sentinel SAP solution workspace |
https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-function-reference |
| Log and table schema reference for Sentinel SAP solution |
https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-log-reference |
| Reference for Sentinel SAP security content and rules |
https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-security-content |
| Stop SAP log collection and disable Sentinel connector |
https://learn.microsoft.com/en-us/azure/sentinel/sap/stop-collection |
| Configure scheduled analytics rules in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/scheduled-rules-overview |
| Use Microsoft Sentinel security alert schema |
https://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema |
| Map Sentinel tables to their data connectors |
https://learn.microsoft.com/en-us/azure/sentinel/sentinel-tables-connectors-reference |
| Use customizable anomaly detection in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/soc-ml-anomalies |
| Prepare prerequisites for Microsoft Sentinel SIEM solutions |
https://learn.microsoft.com/en-us/azure/sentinel/solution-setup-essentials |
| Configure and use summary rules to aggregate Sentinel data |
https://learn.microsoft.com/en-us/azure/sentinel/summary-rules |
| Surface custom event details in Sentinel alerts |
https://learn.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts |
| Configure threat intelligence integrations in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/threat-intelligence-integration |
| Reference for Sentinel UEBA entity enrichments |
https://learn.microsoft.com/en-us/azure/sentinel/ueba-reference |
| Configure unified connectors to integrate with Microsoft Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/unified-connector-integration |
| Apply built-in Sentinel watchlist template schemas |
https://learn.microsoft.com/en-us/azure/sentinel/watchlist-schemas |
| Select Windows security event sets for Sentinel ingestion |
https://learn.microsoft.com/en-us/azure/sentinel/windows-security-event-id-reference |
| Create and tune anomaly analytics rules in Sentinel |
https://learn.microsoft.com/en-us/azure/sentinel/work-with-anomaly-rules |