From the course: Implementing and Administering Microsoft Sentinel
Need a central point of analysis for security events?
From the course: Implementing and Administering Microsoft Sentinel
Need a central point of analysis for security events?
- [Pete] Microsoft Sentinel, Microsoft's cloud-based security information and event management offering brings new capabilities to Azure as a central point of aggregation and analysis of security event. And it's also an important area of knowledge for security professionals focused on Microsoft and the cloud. Onboarding and data ingestion is where it all begins. And we'll cover how to connect Microsoft and third-party data sources to Sentinel. Then, we'll look at how to configure rules to detect and alert on anomalous activity in your environment. And our journey wouldn't be complete without exploring how to investigate incidents and proactively hunt for suspicious activities, as well as automate incident response. Then we'll finish our trip with a look at visualizing all of this data to deliver clear insights in an easy to consume format. Hi, I'm Pete Zerger, consultant, speaker, author, and Microsoft MVP. And I'm excited to be your guide in learning more about Microsoft Sentinel. So grab a coffee and a seat and we'll get started.
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.