Love the time and effort you put in the coffee edit😁
@yt0ng6463 жыл бұрын
You are doing a fantastic job here, thanks a lot !
@Christian-np6je2 жыл бұрын
Awesome video and summary! Thanks a lot!
@polonia662 жыл бұрын
HI, thank you for your great videos. I have question about 42:51 If i would like to set playbook to block the user, what is the best way to do it? as i can see in your case - you add URL with username? so this playbook will be just for one user, how to do with case of any user?
@AzureVlog2 жыл бұрын
You can use variables in the URI of the HTTP activity. You use the "Entities - Get Account" activity to retrieve the username. Then use that username as variable in the URI. It is actually quite bad that I "hardcoded" the username in the URI of the HTTP activity.
@polonia662 жыл бұрын
@@AzureVlog thank you so much!
@shijin_suresh Жыл бұрын
Great Job! Thanks
@motorhead17918 ай бұрын
In sentinel log in OperationName column nothing is appearing what to do?
@wilkinsanchez87373 жыл бұрын
Excellent video. How do you keep track of your expenses when doing these labs? How much money do you usually spend? Is there a way I could do things like this in a lab environment without worrying for a big bill?
@AzureVlog Жыл бұрын
As long as you don't ingest that much data into Microsoft Sentinel, it isn't expensive. You pay per GB that gets ingested into Sentinel. Another way to keep things within budget, is to delete resources after finishing your lab.
@paul.delasaux3 жыл бұрын
Keep it up! These are good.
@bala007raju2 жыл бұрын
very nice video , thanks lot
@progod6017 Жыл бұрын
Good video
@jytan7402 жыл бұрын
is there any guide that can help splunk users translate from SPL to KQL?