The Advanced SIEM Information Model (ASIM): Now Built into Microsoft Sentinel

  Рет қаралды 5,255

Microsoft Security Community

Microsoft Security Community

Күн бұрын

Wednesday, March 9, 2022 | 08:00AM - 9:00AM (PST, Redmond Time)
Microsoft Sentinel Webinar | The Advanced SIEM Information Model (ASIM): Now Built into Microsoft Sentinel
Presenter(s): Ofer Shezaf
Description:
Working with multiple data types and sources is a challenge: Understanding different schemas and creating a unique set of analytics rules, workbooks, and hunting queries for each data source. Now that ASIM is built into Microsoft Sentinel, we will show you how to best use ASIM to use Microsoft Sentinel without worrying about each source's details. Use queries across all your data sources and write simpler and more robust analytic rules and hunting queries.
Advanced Security Information Model (ASIM) security content: docs.microsoft.com/en-us/azur...
To ensure you hear about future Microsoft Sentinel webinars and other developments, make sure you join our community by going to aka.ms/SecurityCommunity
#MicrosoftSentinel #ASIM #Normalization

Пікірлер: 4
@georgeollis
@georgeollis 2 жыл бұрын
This was a super helpful video. Great benefits!
@stubstunner
@stubstunner 2 жыл бұрын
Does ASIM come enabled or do I have to do something special to search the ASIM tables?
@MicrosoftSecurityCommunity
@MicrosoftSecurityCommunity 2 жыл бұрын
Hi Dan, please direct your questions directly to Microsoft Sentinel forum at aka.ms/MicrosoftSentinelCommunity. Someone from our engineering team will get back to you. Thank you for watching!
@rafaelruales6871
@rafaelruales6871 2 жыл бұрын
it looks like they have deployed already information model parsers to LA workspaces, you should be able to search them
Create Large Watchlists up to 500MB in Microsoft Sentinel
2:25
Microsoft Security Community
Рет қаралды 1,2 М.
Heartwarming: Stranger Saves Puppy from Hot Car #shorts
00:22
Fabiosa Best Lifehacks
Рет қаралды 21 МЛН
1❤️
00:17
Nonomen ノノメン
Рет қаралды 13 МЛН
DO YOU HAVE FRIENDS LIKE THIS?
00:17
dednahype
Рет қаралды 93 МЛН
Transforming Data at Ingestion Time in Microsoft Sentinel | Microsoft Sentinel Webinar
51:23
Become a Jupyter Notebooks Ninja - MSTICPy Fundamentals to Build Your Own Notebooks
56:15
Data normalization and transformation | Microsoft Sentinel in the Field #12
17:23
Joe Biden full press conference (July 11, 2024)
58:40
WFAA
Рет қаралды 336 М.
Audit Services
50:23
Microsoft Security Community
Рет қаралды 150
Я УКРАЛ ТЕЛЕФОН В МИЛАНЕ
9:18
Игорь Линк
Рет қаралды 55 М.
Tag her 🤭💞 #miniphone #smartphone #iphone #samsung #fyp
0:11
Pockify™
Рет қаралды 38 МЛН