Skip to main content

sentinel

Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. Covers workspace design, data connectors, ingestion tiers (Analytics/Basic/Auxiliary/ADX), analytics rules, hunting, watchlists, automation playbooks, and cost/commitment-tier optimisation. WHEN: deploy Microsoft Sentinel, design SIEM, onboard data connectors, write analytics rule, KQL detection, Sentinel playbook, SOAR automation, Sentinel cost optimization, log ingestion tiers, commitment tier, Sentinel workspace design, how do I set up a SIEM, collect logs from third-party tools, ingest firewall or Linux syslog into Azure, write a detection rule, automate incident response, how much does Sentinel cost, Auxiliary logs, Basic logs, ADX archive, codeless connector. DO NOT USE when the goal is correlating Microsoft 365 XDR alerts into incidents (use defender-xdr) or onboarding Sentinel into the unified Defender portal (use unified-secops-platform).

الانتقال إلى التثبيت

معلومات المصدر

المستودع
vinayaklatthe/microsoft-security-skills
آخر نشاط في المصدر
١١ يونيو ٢٠٢٦ في ١٢:٠١
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
١٧٠
التفرعات
٣٥

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.