Building Microsoft Sentinel Usecases with automation using playbooks

  Рет қаралды 8,535

AzureVlog

AzureVlog

Күн бұрын

Пікірлер: 16
@motorhead1791
@motorhead1791 5 ай бұрын
In sentinel log in OperationName column nothing is appearing what to do?
@progod6017
@progod6017 Жыл бұрын
Good video
@IamSahilVerma
@IamSahilVerma 3 жыл бұрын
First like from Canada...
@shijin_suresh
@shijin_suresh Жыл бұрын
Great Job! Thanks
@wilkinsanchez8737
@wilkinsanchez8737 2 жыл бұрын
Excellent video. How do you keep track of your expenses when doing these labs? How much money do you usually spend? Is there a way I could do things like this in a lab environment without worrying for a big bill?
@AzureVlog
@AzureVlog Жыл бұрын
As long as you don't ingest that much data into Microsoft Sentinel, it isn't expensive. You pay per GB that gets ingested into Sentinel. Another way to keep things within budget, is to delete resources after finishing your lab.
@yt0ng646
@yt0ng646 3 жыл бұрын
You are doing a fantastic job here, thanks a lot !
@jytan740
@jytan740 2 жыл бұрын
is there any guide that can help splunk users translate from SPL to KQL?
@Christian-np6je
@Christian-np6je 2 жыл бұрын
Awesome video and summary! Thanks a lot!
@bala007raju
@bala007raju 2 жыл бұрын
very nice video , thanks lot
@willemplug3366
@willemplug3366 2 жыл бұрын
Love the time and effort you put in the coffee edit😁
@IamSahilVerma
@IamSahilVerma 3 жыл бұрын
First like from Canada..
@polonia66
@polonia66 Жыл бұрын
HI, thank you for your great videos. I have question about 42:51 If i would like to set playbook to block the user, what is the best way to do it? as i can see in your case - you add URL with username? so this playbook will be just for one user, how to do with case of any user?
@AzureVlog
@AzureVlog Жыл бұрын
You can use variables in the URI of the HTTP activity. You use the "Entities - Get Account" activity to retrieve the username. Then use that username as variable in the URI. It is actually quite bad that I "hardcoded" the username in the URI of the HTTP activity.
@polonia66
@polonia66 Жыл бұрын
@@AzureVlog thank you so much!
@pauldelasaux5756
@pauldelasaux5756 3 жыл бұрын
Keep it up! These are good.
Using Azure Sentinel with Logstash
18:03
AzureVlog
Рет қаралды 5 М.
Working with Threat Intelligence in Azure Sentinel
17:25
AzureVlog
Рет қаралды 4,7 М.
БЕЛКА СЬЕЛА КОТЕНКА?#cat
00:13
Лайки Like
Рет қаралды 2,5 МЛН
Watermelon magic box! #shorts by Leisi Crazy
00:20
Leisi Crazy
Рет қаралды 32 МЛН
Getting started with Threat Hunting in Microsoft Sentinel
13:22
AzureVlog
Рет қаралды 4,5 М.
RETIRED. PLEASE SEE NEW VERION! AZ-104 Microsoft AZ-104 Study Cram - OVER 1,000,000 VIEWS
3:45:01
John Savill's Technical Training
Рет қаралды 1 МЛН
Setting up alert rules in Azure Sentinel
10:14
AzureVlog
Рет қаралды 10 М.
Microsoft Sentinel Setup and Configuration (2023 edition)
24:09
Microsoft Power Platform Fundamentals (PL-900) - Full Course Pass the Exam!
3:26:00
Export your SOAR Playbooks with ease | Microsoft Sentinel in the Field #7
12:05
Давайте поцарапаем iPhone 16 Pro Max!
0:57
Wylsacom
Рет қаралды 1,6 МЛН
The force of electromagnetic eddy currents
0:31
Nikola Toy
Рет қаралды 14 МЛН
Обзор на 16 айфон
1:01
Тыковка из Германии
Рет қаралды 545 М.