Using the Microsoft Sentinel Information Model Process Events Schema ASIM

  Рет қаралды 1,836

CraigCloudITPro

CraigCloudITPro

Күн бұрын

Пікірлер: 7
@travelmore9626
@travelmore9626 3 жыл бұрын
Thanks for sharing this info Craig. Why do some KQL functions begin with "im" and others with "vim" ? What do these stand for? Thanks
@CraigCloudITPro
@CraigCloudITPro 3 жыл бұрын
Hey TravelMore, very good question and quite tricky as well, so IM means Source Agnostic for example the im source agnostic parser name would be imDns, then vim is Source Specific, for example vimDnsAzureFirewall or vimDnsGcp (so these are all the parses contained inside the imDns parse) I hope that answers your question :)
@travelmore9626
@travelmore9626 3 жыл бұрын
@@CraigCloudITPro ahh that makes sense and a sensible way of differentiating. Cheers Craig!
@olafhoogstad446
@olafhoogstad446 5 ай бұрын
Hi Craig, first of all, thank you so much for your videos, they really help me understand a lot on the SC-200 course and exam I am currently studying for! If I understand correctly, for parsers there are (generally speaking) the following types: _Im_ = Built-in UNIFYING parser Im = Built-in WORKSPACE DEPLOYED parser _Im__ = Built-in SOURCE-SPECIFIC parser vim = WORKSPACE-DEPLOYED SOURCE SPECIFIC parser A corresponding set of parsers that use _ASim_ and ASim are also available. It is not completely clear to me when to use these last parsers, actually. Could you (or someone else of course) help me out please? Thank you :)
@CraigCloudITPro
@CraigCloudITPro 5 ай бұрын
Hi Olaf, Thank you for your kind words! I’m glad my videos have been helpful to you in your SC-200 course and exam preparation. To clarify your understanding of parsers in Microsoft Sentinel: • Im: Built-in UNIFYING parser. • Im: Built-in WORKSPACE DEPLOYED parser. • Im_: Built-in SOURCE-SPECIFIC parser. • vim: WORKSPACE-DEPLOYED SOURCE SPECIFIC parser. When to use ASIM parsers: • Use ASim when you need a built-in unifying parser for a specific schema across different sources. This helps in normalizing data from various sources into a common schema. • Use ASim for workspace-deployed parsers that are customized for your specific environment and use cases. These are useful when you have specific log sources that require customized parsing rules. These ASIM parsers are especially valuable when dealing with complex environments with multiple data sources, as they help in unifying and simplifying the analysis process. I hope this helps! Let me know if you have any more questions.
@MultiRam73
@MultiRam73 6 ай бұрын
Hats off to you Craig! It was mindblowing the way you simplified the whole jargon, I feel so rich with the knowledge you shared here, I was so poor before this class
@CraigCloudITPro
@CraigCloudITPro 6 ай бұрын
@MultiRam73 thank you so much for your kind words :)
Understanding and Mastering Microsoft Sentinel Analytics
15:42
CraigCloudITPro
Рет қаралды 1,3 М.
Microsoft Sentinel Threat Hunting Deep Dive
24:03
CraigCloudITPro
Рет қаралды 6 М.
BAYGUYSTAN | 1 СЕРИЯ | bayGUYS
36:55
bayGUYS
Рет қаралды 1,9 МЛН
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН
IL'HAN - Qalqam | Official Music Video
03:17
Ilhan Ihsanov
Рет қаралды 700 М.
Data normalization and transformation | Microsoft Sentinel in the Field #12
17:23
Architecting and Designing Microsoft Sentinel
12:39
CraigCloudITPro
Рет қаралды 4,8 М.
Incident Response Procedures with Microsoft Sentinel
15:26
CraigCloudITPro
Рет қаралды 3 М.
Get Started with Azure Sentinel
18:22
Andy Malone MVP
Рет қаралды 43 М.
Hunting Malware with Microsoft Sentinel Threat Intelligence
20:41
CraigCloudITPro
Рет қаралды 1,5 М.
CoPilot for Microsoft 365 Security Risks
19:51
CraigCloudITPro
Рет қаралды 1,3 М.
Microsoft Sentinel Best Practice for Admin Users
18:31
CraigCloudITPro
Рет қаралды 1,6 М.
The Advanced SIEM Information Model (ASIM): Now Built into Microsoft Sentinel
55:00
Microsoft Security Community
Рет қаралды 6 М.
The Cyber Kill Chain and Microsoft Sentinel
19:44
CraigCloudITPro
Рет қаралды 929