❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Where did functions move from Sentinel to Defender ?

Hello everyone,
I connected some of my VMs to Microsoft Sentinel to learn a bit about the solution, create analytics rules, Workbooks, etc.

But in the middle of me using Sentinel, functions started "migrating" to Defender portal. And sometimes they are visible in Sentinel, sometimes not, you only get "his page has been moved to the Defender portal for the optimal, unified SecOps experience. Click here to go to the Defender portal"

Is there some mapping of functions from Sentinel to Defender?

Like I am really missing the "Overview" tab where I could see the number of events, usage, incidents, etc.
It worked for my 5 minutes ago, but now it also moved to Defender.

Where would I find the equivalent of "Overview" in Defender?
Keep in mind, I have no Defender for endpoints, only Windows AMA connectors.

submitted by /u/Delicious-Purple-689
[link] [comments]

What am I doing wrong in deploying Sentinel?

What am I doing wrong in deploying Sentinel?

Hello all
I am trying to connect a single DC from my on-prem deployment to Azure and Sentinel.

I have zero experience with Azure, but I was expecting the documentation to be more clear, and the Azure UI to be more intuitive.

https://preview.redd.it/j8vxcurk3bpf1.png?width=731&format=png&auto=webp&s=fe71d0b8d6d3ab4123bcf2577e731c56d1d297df

https://preview.redd.it/9wkw65on3bpf1.png?width=1458&format=png&auto=webp&s=d07b4240569128bb8c5b37bd7a95bd493c98d2a5

You can see here that I installed Azure Arc on my Windows 2022 host, and that the machine is visible in Azure, but I just cannot connect the dots to start seeing logs and to display them in Sentinel.
What am I doing wrong?

EDIT: I am only using this for testing so I have the Azure free 200€ subscription for 30 days.

submitted by /u/Delicious-Purple-689
[link] [comments]
❌
❌