KQL-based detection in Microsoft Sentinel that searches ingested data, generates alerts and bundles them into incidents. Rules identify threats but do not fix them.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Analytics rule in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
Related terms
- Entity mapping
Part of an analytics rule's configuration: you link columns returned by its query to entity types such as host, IP address or account. Sentinel alerts then carry those entities, which helps when correlating and investigating them. Each rule allows a maximum of 10.
- Incident correlation
Controls whether Sentinel analytics rule alerts get grouped by the Defender XDR correlation engine. For the tenant it starts switched off, but each rule can set its own value.
- ML Behavior Analytics
A preview Microsoft Sentinel analytics rule type, which cannot be customised, that applies Microsoft's own machine learning models to user history, geolocation and IP data to spot unusual RDP and SSH sign-ins.
- NRT rule
Short for near-real-time rule. This Microsoft Sentinel analytics rule fires each minute, looking at one minute of ingested data with a two-minute lag; up to 50 can be enabled, and 100 can exist counting disabled rules.
- Playbook
Response automation for Microsoft Sentinel built as a Logic Apps workflow, triggered manually or by an automation rule to do things like block IPs, open tickets or assign incidents. Launching one directly from an analytics rule is retired.