The Must Learn KQL Community Discussion Board

Among all the myriad of cool things that the Must Learn KQL series has birthed, there's now also a Community Discussion board available. The Discussion board is designed to enable Q&A, feedback, ongoing discussions, code posts, polls, and on and on. Must Learn KQL Discussion Board Jump out to the following link to get engaged … Continue reading The Must Learn KQL Community Discussion Board

Is Moving the Sentinel Workspace to Another Resource Group or Subscription Supported?

This is a common question and one that needs both an answer and a Docs location to always find the answer. Digging around in the Microsoft Sentinel Docs may not yield the answer you're looking for. The answer is located in the Azure Monitor Doc for Workspace move considerations (URL: https://docs.microsoft.com/en-us/azure/azure-monitor/logs/move-workspace#workspace-move-considerations). Per the Doc: Currently, … Continue reading Is Moving the Sentinel Workspace to Another Resource Group or Subscription Supported?

How to: Automate On-Premises AD Users to Microsoft Sentinel Watchlist

Watchlists in Microsoft Sentinel allow you to correlate data from a data source you provide with the events in your Microsoft Sentinel environment. For example, you might create a watchlist with a list of high-value assets, terminated employees, or service accounts in your environment. Microsoft Sentinel customers often ask if there is a chance to … Continue reading How to: Automate On-Premises AD Users to Microsoft Sentinel Watchlist