Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
Also called Azure Sentinel.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-103SC-900SC-200ALZ
Each book explains Microsoft Sentinel in context, with comparison tables and the common traps.
Terms in this definition
- SIEM
A platform that gathers and correlates security logs to detect threats and raise alerts. In Azure the cloud SIEM is Microsoft Sentinel, which runs on a Log Analytics workspace.
- SOAR
Security orchestration, automation and response: tools that receive alerts from a SIEM and other sources and react to them automatically using workflows known as playbooks. Microsoft Sentinel offers SOAR as well as SIEM.
- Log Analytics workspace
Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.
Related terms
- Analytics rule
KQL-based detection in Microsoft Sentinel that searches ingested data, generates alerts and bundles them into incidents. Rules identify threats but do not fix them.
- Analytics tier
Hot data tier of Microsoft Sentinel supporting hunting, detections and every Sentinel feature; its analytics retention can be extended to as much as two years.
- Anomaly rule
A machine-learning rule in Microsoft Sentinel, listed on the Anomalies tab of Analytics, that learns normal behaviour and records what it finds in the Anomalies table rather than generating alerts. These rules are on by default, and you tune one by duplicating it.
- ASIM
The Advanced Security Information Model in Microsoft Sentinel, which maps data from many vendors onto shared schemas so one query or detection rule works whatever the source.
- ASIM parsers
Short for Advanced Security Information Model parsers: KQL functions that map Microsoft Sentinel data onto shared schemas when queried. That happens after ingestion has been charged, so ingestion costs are unaffected.
- Automation rule
Microsoft Sentinel rule triggered when an incident or alert from any source is created or updated, used to centrally set status, assign owners, apply tags and launch playbooks.
- Azure Activity
Connector for Microsoft Sentinel that streams each subscription's activity log, via diagnostic settings, into the AzureActivity table. A subscription that was hooked up the older, legacy way needs disconnecting before you switch over.
- BehaviorAnalytics
Holds enriched UEBA events in Microsoft Sentinel and feeds entity pages. Each row carries an InvestigationPriority between 0 and 10 indicating how far from normal the event is.