❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Unable to run cross workspace queries

10 October 2025 at 18:03
Unable to run cross workspace queries

Has anyone encountered issues when running cross-workspace queries within the same tenant? I faced this before,it only worked when I referenced the workspace ID instead of the name in the query. Tried importing the JSON again, but the error persists.

https://preview.redd.it/7qlwczw7xcuf1.png?width=814&format=png&auto=webp&s=660d27167991687773d9f8bd5c53eb2a16228ff3

submitted by /u/dutchhboii
[link] [comments]

Query History Unavailable for current Month

21 August 2025 at 05:54

Anyone else noticing that query history isn’t showing anything for the current month? Ours only goes up to the end of July 2025. Seems to be affecting everyone on our team in the W. Europe region curious if others are seeing the same thing?

submitted by /u/dutchhboii
[link] [comments]

Data log export to Eventhub

21 July 2025 at 03:20

I'm trying to export only a specific log type from the CommonSecurityLog, but I'm having trouble figuring out the process. I don't want to export the entire set of CEF logs, and I noticed that functions aren't available when configuring data export. Is there a method to export just one log type from the CEF logs to Event Hub? for ex logs from only palo alto and not fortinet under CEF.

submitted by /u/dutchhboii
[link] [comments]

Retiring Azure Portal - July 1, 2026

Today, we’re announcing that we are moving to the next phase of the transition with a target to retire the Azure portal for Microsoft Sentinel by July 1, 2026. Customers not yet using the Defender portal should plan their transition accordingly.

https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613

What are your thoughts on this,folks? Do they genuinely believe this is achievable? I understand the goal is to move toward Defender XDR, but I’m still uncertain about how this transition might impact us.

Especially the fusion alerts, graph Api automations , logicapps, tasks and RBAC.

submitted by /u/dutchhboii
[link] [comments]

CI/CD Pipelines via Azure Devops

CI/CD Pipelines via Azure Devops

Has anyone here implemented this flow? What is it like to have version control and centralized deployment, along with rules backup? Do you still need to use GitHub for backend code control and use variables for whitelisting in DevOps? The idea is to avoid storing our detections and whitelists in GitHub repositories for security reasons.

https://preview.redd.it/avc2ym5m7y0f1.png?width=1498&format=png&auto=webp&s=0f73992993ce1377442558809819d99969a8cfc2

submitted by /u/dutchhboii
[link] [comments]

Azure Arc Onboarding - TIer 0 Servers

We are currently in the process of migrating servers from MMA to AMA and, along the way, evaluating best practices for managing Domain Controllers in Azure. While we have implemented Defender for Identity on the DCs and addressed RBAC configurations, we're still navigating through some Auditor-related challenges. That said, beyond onboarding the DCs via Azure Arc, are there any recommended best practices for collecting security-relevant events from Domain Controllers?

submitted by /u/dutchhboii
[link] [comments]

Incidents Stopped Firing - Sentinel

28 April 2025 at 15:13

Is anyone else experiencing an issue where Sentinel is not generating any incidents in the console, despite the analytical rules (both scheduled and NRT) showing successful run statuses? It's unusual to have no incidents triggered for over three hours. No health issues have been observed with the log ingestion either.

submitted by /u/dutchhboii
[link] [comments]
❌
❌