Sentinel
Resource Icon

Resource Overview
Azure Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that collects and analyzes various security data sources to detect threats and automate incident response.
It is built on Log Analytics Workspace and supports integrated security operations by configuring alert rules and connecting Microsoft security products and external data connectors.
Associated Resources
Parent Resources
Connected Resources
Resource Configuration
linked_workspace_name: Name of the Log Analytics Workspace to which Sentinel is connectedconnect_security_center: Whether to connect the Microsoft Defender for Cloud Data Connector -true,falseconnect_threat_intelligence: Whether to connect the Threat Intelligence Platform (Preview) Data Connector -true,falseconnect_advanced_threat_protection: Whether to connect the Microsoft Defender for Identity Data Connector -true,falseconnect_microsoft_defender: Whether to connect the Microsoft Defender for Endpoint Data Connector -true,falseconnect_office_365: Whether to connect the Office 365 Data Connector -true,falseconnect_cloud_app_security: Whether to connect the Microsoft Defender for Cloud Apps Data Connector -true,falsefusion_rule_rule_guid: List of Fusion Rule GUIDsbehavior_analytics_rule_guid: List of ML Behavior Analytics Rule GUIDstag: Tags used to categorize resources
MS Security Incident Alert Rule (alert_rule_incident)
alert_rule_incident.display_name: Display name of the MS Security Incident Alert Rulealert_rule_incident.product: Microsoft security service that generates alerts -Azure Active Directory Identity Protection,Azure Advanced Threat Protection,Azure Security Center,Azure Security Center for IoT,Microsoft Cloud App Security,Microsoft Defender Advanced Threat Protection,Office 365 Advanced Threat Protectionalert_rule_incident.severity: Severity levels for generating incidents -High,Medium,Low,Informational
Scheduled Alert Rule (alert_rule_scheduled)
alert_rule_scheduled.display_name: Display name of the Scheduled Alert Rulealert_rule_scheduled.severity: Severity of the Scheduled Alert Rule -High,Medium,Low,Informationalalert_rule_scheduled.query: Query statement of the Scheduled Alert Rule