Reading view

There are new articles available, click to refresh the page.

Unable to run cross workspace queries

Unable to run cross workspace queries

Has anyone encountered issues when running cross-workspace queries within the same tenant? I faced this before,it only worked when I referenced the workspace ID instead of the name in the query. Tried importing the JSON again, but the error persists.

https://preview.redd.it/7qlwczw7xcuf1.png?width=814&format=png&auto=webp&s=660d27167991687773d9f8bd5c53eb2a16228ff3

submitted by /u/dutchhboii
[link] [comments]

Data log export to Eventhub

I'm trying to export only a specific log type from the CommonSecurityLog, but I'm having trouble figuring out the process. I don't want to export the entire set of CEF logs, and I noticed that functions aren't available when configuring data export. Is there a method to export just one log type from the CEF logs to Event Hub? for ex logs from only palo alto and not fortinet under CEF.

submitted by /u/dutchhboii
[link] [comments]

Retiring Azure Portal - July 1, 2026

Today, we’re announcing that we are moving to the next phase of the transition with a target to retire the Azure portal for Microsoft Sentinel by July 1, 2026. Customers not yet using the Defender portal should plan their transition accordingly.

https://techcommunity.microsoft.com/blog/microsoft-security-blog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4428613

What are your thoughts on this,folks? Do they genuinely believe this is achievable? I understand the goal is to move toward Defender XDR, but I’m still uncertain about how this transition might impact us.

Especially the fusion alerts, graph Api automations , logicapps, tasks and RBAC.

submitted by /u/dutchhboii
[link] [comments]

CI/CD Pipelines via Azure Devops

CI/CD Pipelines via Azure Devops

Has anyone here implemented this flow? What is it like to have version control and centralized deployment, along with rules backup? Do you still need to use GitHub for backend code control and use variables for whitelisting in DevOps? The idea is to avoid storing our detections and whitelists in GitHub repositories for security reasons.

https://preview.redd.it/avc2ym5m7y0f1.png?width=1498&format=png&auto=webp&s=0f73992993ce1377442558809819d99969a8cfc2

submitted by /u/dutchhboii
[link] [comments]

Azure Arc Onboarding - TIer 0 Servers

We are currently in the process of migrating servers from MMA to AMA and, along the way, evaluating best practices for managing Domain Controllers in Azure. While we have implemented Defender for Identity on the DCs and addressed RBAC configurations, we're still navigating through some Auditor-related challenges. That said, beyond onboarding the DCs via Azure Arc, are there any recommended best practices for collecting security-relevant events from Domain Controllers?

submitted by /u/dutchhboii
[link] [comments]
❌