Get Started with Azure Sentinel

  Рет қаралды 41,127

Andy Malone MVP

Andy Malone MVP

Күн бұрын

Пікірлер: 92
@FreshAzoxy
@FreshAzoxy 11 ай бұрын
What a great video - Cheers Andy!
@AndyMaloneMVP
@AndyMaloneMVP 11 ай бұрын
Thank you! Cheers!
@cam1495
@cam1495 Жыл бұрын
This was so clear and easy to follow, you are a true MVP Andy.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Glad you liked it!
@Tony-dp1rl
@Tony-dp1rl Жыл бұрын
I love the optimism of "MAY" incur additional charges. LOL.
@onder452
@onder452 Ай бұрын
Hi Andy, why you skipped Analytics section after Data Connector, I came for it :)
@jhavlick1
@jhavlick1 Жыл бұрын
You say several times in the video that SIEM is Security "Incident" and Event Management, but the definition according to Gartner, IBM and others is Security "Information" & Event Management. Is that intentional?
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
I stand by my definition :-) According to Microsoft
@icewatermedia
@icewatermedia 8 ай бұрын
​@@AndyMaloneMVPWhy do you keep deleting my post? I'm only trying to help and I like your content. If someone new to cybersecurity follows your video, and gets asked "What does SIEM mean" in a job interview, they may reply with the wrong answer and fail that question. Why not just own up to your mistake and correct it if you're really trying to help people?
@AndyMaloneMVP
@AndyMaloneMVP 8 ай бұрын
@@icewatermedia I not delete content that may contain offensive language. Beyond that sometimes yt sometimes deletes content which is beyond my control. That said I do appreciate your feedback thanks 👍😊
@icewatermedia
@icewatermedia 8 ай бұрын
​@@AndyMaloneMVP Thanks for your reply! I think yt may have deleted my comment because I posted a reference link to Microsoft's definition of SIEM. For the benefit of anyone reading this, there's a mistake in the video for what SIEM means. Several times in the video, SIEM is defined as "Security Event and Incident Management" (which would be SEIM and actually could work if it were correct). However, according to Microsoft and the rest of the cybersecurity industry, SIEM is an acronym that stands for "Security Information and Event Management". Microsoft's definition can be found by searching Google for "What is SIEM Microsoft".
@taiwoojoko1030
@taiwoojoko1030 8 ай бұрын
Can you please teach how logs can be force-pulled from the log analytics on Sentinel using Query?
@pjchacon
@pjchacon Жыл бұрын
You may want to rename this video. The brand Azure Sentinel has not been used since before Covid. Also, this is a tip on Microsoft branding: if the name starts with Windows or Azure, it means that the product only works on that platform. When the product is named Microsoft, or renamed to Microsoft [Name], like in the case of Microsoft Sentinel, it means that the product is either multi-platform or multi-cloud. When Sentinel started supporting AWS, it was renamed to Microsoft Sentinel.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Hehe well spotted.
@francescobedinijacobini
@francescobedinijacobini 2 жыл бұрын
GREAT video as always! A note on pricing: Azure Sentinel requires a separate Azure subscription, but it is indeed worth the investment! Microsoft offers a free 30 day trial to allow users to familiarise with the capabilities.
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
Well said, and thanks for your input. Really useful. 😊 👍
@PraveenKambhampatiMyVideos
@PraveenKambhampatiMyVideos Жыл бұрын
You are an awesome trainer Andy !! Thank you for the session !!
@f4ked640
@f4ked640 2 жыл бұрын
Such an Amazing video, this feature is one of most interesting that we can find in Microsoft services, I was waiting for you to talk about it
@vjp724
@vjp724 7 ай бұрын
This was a great video. Thank you. I have managed NOCs for many years. Can MS Sentinel be considered a NOC monitoring also, not just for security? I ask because you are literally collecting logs from almost any system, which would include system failures. These failures could be pre programed against priority levels which could be projected on a event monitoring dashboard. So I find Sentinel is not just a security event and incident monitoring machine. It's for everything. Would this be correct understanding? Thank you again. Your material is awesome mate! I am from UK also :)
@AndyMaloneMVP
@AndyMaloneMVP 7 ай бұрын
Yes, Sentinel is far more than just a simple monitoring system. It has intelligent systems built on AI and machine learning technologies which perform detailed and complex behavioural analytics to look for any potential anomalies. As I said in the video it’s considered next generation security. For more documentation I would read learning.microsoft.com. Yeah you’ll find all the documentation. Thanks again and all the best Andy 😊
@adriansasayah7527
@adriansasayah7527 Жыл бұрын
Is Sentinel able to take signals from other Azure services like Monitor, Insights to raise an incident? Perhaps like what AWS offers via its Systems Manager Incident Manager.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Absolutley 100%
@rojabalasubramaniyan1150
@rojabalasubramaniyan1150 6 күн бұрын
Great video. Because of this video, I got a new opportunity in MNC. Thank you so much.
@AndyMaloneMVP
@AndyMaloneMVP 5 күн бұрын
Awesome👍
@rachaelongalo6296
@rachaelongalo6296 Жыл бұрын
Thanks, well explained
@mshajan
@mshajan 2 жыл бұрын
The best resources and the best channel for Microsoft learning!!! Thanks Andy.. Keep going..
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
Thanks, will do!
@Boreczek1988
@Boreczek1988 Жыл бұрын
I`m planning to deploy Sentinel in my organization and your tutorial was a great starting point. Thank you.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
You’re very welcome and thank you 😊
@AB-me8jf
@AB-me8jf 6 ай бұрын
Which certification exam we have to write for Azure Sentinel ?
@AndyMaloneMVP
@AndyMaloneMVP 6 ай бұрын
SC-200
@osman_gedik
@osman_gedik 23 күн бұрын
The overview changed a lot, what is the difference or benefits of the new overview ?
@AndyMaloneMVP
@AndyMaloneMVP 23 күн бұрын
An integrated portal Microsoft 365 XDR
@eliasmusic7426
@eliasmusic7426 Жыл бұрын
Hi Andy, is there anyway I can get that sample data to import into sentinel and play with it, Please
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
I had demo data that I believe you can generate a sample either in Sentinel, Defender for endpoint of on Microsoft Learn.
@amiblueful
@amiblueful 10 ай бұрын
Thank you, Andy. I have to do some documentation about integrating Sentinel with our product. It was a bit of a black hole to me.
@deeptimudiraj5891
@deeptimudiraj5891 Ай бұрын
It was so clear and easy to understand...well explained....Thank you.
@arvehov8402
@arvehov8402 2 жыл бұрын
Another great video. Doing my AZ-500 next week, and your videos are of great help.
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
Good luck!
@corywest3071
@corywest3071 8 ай бұрын
HA! even the microsoft mvp is using a mac
@AndyMaloneMVP
@AndyMaloneMVP 8 ай бұрын
Absolutley I'm all in Apple. For devices!
@D87-t8e
@D87-t8e Жыл бұрын
what license do you need to use the sentinel platform? I have the E5 license, but it's still saying subscription is not enabled.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
E5 plus additional costs. but you can take advantage of an E5 benefit. 5Mb data per day.
@D87-t8e
@D87-t8e Жыл бұрын
@@AndyMaloneMVP thanks
@MrNoor3
@MrNoor3 Жыл бұрын
How to use Microsoft sentinel in multiple tenant?
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Here you go learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers
@stantkatchenko1341
@stantkatchenko1341 Жыл бұрын
Superior training skills based on the very solid experience..
@jordanpomeroy1937
@jordanpomeroy1937 11 ай бұрын
Hi Andy - a question for you - what is the difference between defender and sentinel? does Sentinel proactively monitor your entire estate for threats, whereas defender scans for specific viruses etc? thanks!
@AndyMaloneMVP
@AndyMaloneMVP 11 ай бұрын
Microsoft defender for endpoint of the defence tools that manage the policies and detect potential threats. Sentinel is a monitoring system but also can combine with something called soar. Security operations automated response so if anomalies are detected, they can be auto mediated. Sentinel siem system, or security, incident and event management, which basically collate logs and looks for anomalies. Typically defender and sentinel work together to provide you an important cock in the wheel in the Microsoft zero trust model
@joshuaeuceda4635
@joshuaeuceda4635 Жыл бұрын
Great content as usual , Andy. Appreciate the effort!
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Thanks Joshua, I appreciate that 😊
@tamilselvanelancheran1579
@tamilselvanelancheran1579 Жыл бұрын
Awesome to learn from this video starts right from the way you convey things... Post this, I subscribed immediately and looking for all your videos.....Thank you for sharing... And maybe you could showcase on Azure sentinel right from prerequisites, implementations & best practices also if possible
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
I've done sessions on Sentinel. Check out my Defender playlist.
@mehdibendahou8799
@mehdibendahou8799 Жыл бұрын
Hello Sir and Many thanks for your Channel... I Wonder if you can make a video about EASM New feature (External Attack Surface Management). It is an evolution of the XDR ? Best regards.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
I’ll add it to my list. Thanks for the suggestion.
@sachinmalhotra3709
@sachinmalhotra3709 Жыл бұрын
Thanks for making a wonderful videos, 1 query defender for endpoint or sentinel which has a more scope??
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
They are different products, but they compliment each other perfectly. However, I would have to say that sentinel has a greater scope.
@eerosiljander4622
@eerosiljander4622 Жыл бұрын
Positive attitude, thanks for this. Have a Nice Day. Greeting from Finland
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Thank you very much, greetings from scotland also 😊
@judahtunes2245
@judahtunes2245 Жыл бұрын
Well Spoken on the subject and easy to follow
@anupsah4768
@anupsah4768 Жыл бұрын
Hey andy i am new in sentinel and don't know how to protect my VM with malware using sentinel. can you help on this this?
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
For this, she would need to install defender for endpoint client available in settings in the security centre. Then simply configure policies. For more information check out docs.microsoft.com
@judahtunes2245
@judahtunes2245 Жыл бұрын
Andy, which of your videos can I utilize in assisting me to pass my SC-200 ? ... I know Sentinel is a mjor part of the exam.. thanks sir
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
None in particular, but if you look at the security videos, in particular, all of the defender videos, they are included in the exam
@judahtunes2245
@judahtunes2245 Жыл бұрын
@@AndyMaloneMVP Thank you kindly
@Israelxox
@Israelxox 10 ай бұрын
Best explanation, Sir! 🙏
@sourabhbdr7201
@sourabhbdr7201 Жыл бұрын
Can you please tell me how to get notification when a new incident generated??
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
Create an automation to send you an email
@sourabhbdr7201
@sourabhbdr7201 Жыл бұрын
@@AndyMaloneMVP yes but I want beep sound when unassigned incident occurs
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
No idea sorry other than a txt message or email
@sourabhbdr7201
@sourabhbdr7201 Жыл бұрын
@@AndyMaloneMVP it's ok, thanks for your reply
@todornikolov7286
@todornikolov7286 2 жыл бұрын
Friday learning :) Thank you. Wish you wonderful weekend :)
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
Thank you! You too!
@gregoryigbinoba4778
@gregoryigbinoba4778 2 жыл бұрын
Thanks for the video Andy. How would you differentiate Azure Sentinel to cloud app security broker (CASB) ?
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
A casb connects to your environment for the purpose of monitoring apps and users and has a level of intelligence to look for anomalies. Sentinel collates logs and all the other defender services to look for anomalies in logs. E.g. deletions etc. I can see your confusion though, they do have some similarities 😊
@pjchacon
@pjchacon Жыл бұрын
Microsoft Sentinel is Microsoft's SIEM and SOAR solution. Microsoft CASB solution is Microsoft Defender for Apps, which is part of Microsoft 365 Defender.
@marconecybertwo
@marconecybertwo 11 ай бұрын
Thanks Andy, great content and explanation as always
@AndyMaloneMVP
@AndyMaloneMVP 11 ай бұрын
No worries!
@keyge-jv9hg
@keyge-jv9hg Жыл бұрын
Hey Andy, great video. Does it make sense to connect all the Microsoft services like iot hub, aks clusters, etc to the sentinel platform? I ask because all the services are managed by Microsoft and isn't it senseless to monitor them? Or are there specific use cases from the mittre attack database, that you would say it is a must to activate sentinel. Thank you in advance
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
I love Sentinel. But beware of over monitoring. It can be very expensive. I agree with your IoT Comment though.
@pjchacon
@pjchacon Жыл бұрын
Yes, the idea is to monitor everything from Microsoft Sentinel (including the AWS and GCP components that it supports). However, the first cardinal rule is to make sure that you are only ingesting the alerts/logs that you absolutely need. Pricing is based on ingestion, so the more you ingest, the more you pay. There are price discounts based on committed consumption ("I will consume at least 5GB per month"), but even with this you want to limit ingestion to only what you need. Many Sentinel connectors, and its Codeless Connector Platorm, as well as AMA, now support DCRs (data collection rules) which allow you to filter data pre-ingestion, allowing you to better control your price.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
@@pjchacon Great tips, and I totally agree with you on price!
@sohailsiddique5134
@sohailsiddique5134 Жыл бұрын
excellent
@65giga
@65giga 2 жыл бұрын
Grazie Big
@HawtSauwce
@HawtSauwce Жыл бұрын
Love your content man, thank you.
@AndyMaloneMVP
@AndyMaloneMVP Жыл бұрын
My pleasure!
@soodshubham7671
@soodshubham7671 2 жыл бұрын
Thank you Andy Sir :)
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
You are very welcome
@emmanuelchrispher8958
@emmanuelchrispher8958 2 жыл бұрын
thanks again sir
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
Always welcome
@sunildahiya6363
@sunildahiya6363 2 жыл бұрын
Thanks Andy!!!!
@AndyMaloneMVP
@AndyMaloneMVP 2 жыл бұрын
No worries!
Microsoft Intune From Zero to Hero
39:08
Andy Malone MVP
Рет қаралды 219 М.
Microsoft Sentinel Setup and Configuration (2023 edition)
24:09
Incredible: Teacher builds airplane to teach kids behavior! #shorts
00:32
Fabiosa Stories
Рет қаралды 11 МЛН
Как подписать? 😂 #shorts
00:10
Денис Кукояка
Рет қаралды 8 МЛН
Microsoft Sentinel in just 30 minutes
36:20
Microsoft Academy Hub
Рет қаралды 27 М.
Get Started with Microsoft Defender for 365
24:29
Andy Malone MVP
Рет қаралды 41 М.
Introduction to Azure Sentinel. Part 1 - Foundations
54:21
Netrix Global
Рет қаралды 12 М.
On-board Azure Sentinel-Azure Sentinel Setup & Configuration
7:51
asar cloud Chef
Рет қаралды 9 М.
Get started with Microsoft 365 Defender
36:37
Andy Malone MVP
Рет қаралды 32 М.
Microsoft Entra   The MUST KNOW Guide for Admins
22:48
Andy Malone MVP
Рет қаралды 15 М.
Get started with Microsoft Defender for Cloud
21:03
Andy Malone MVP
Рет қаралды 22 М.
Setup Microsoft Sentinel | Tutorial
15:15
Concepts Work
Рет қаралды 1,6 М.
Deploying Microsoft Sentinel Demo
10:26
Alex de Jong
Рет қаралды 411
Incredible: Teacher builds airplane to teach kids behavior! #shorts
00:32
Fabiosa Stories
Рет қаралды 11 МЛН