azure-sentinel

v2026.09.24

Expert knowledge for Azure Sentinel development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring data connectors, analytics rules, playbooks, ASIM/UEBA, or Sentinel data lake jobs, and other Azure Sentinel related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure Monitor (use azure-monitor), Azure External Attack Surface Management (use azure-external-attack-surface-management).

GitHub
安装命令
npx skhub add microsoftdocs/azure-sentinel
Markdown
SKILL.md

Azure Sentinel Skill

This skill provides expert guidance for Azure Sentinel. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L50Diagnosing and fixing Microsoft Sentinel ingestion, connector, KQL, notebook, MCP, SAP, and analytics rule errors, plus monitoring and troubleshooting scheduled rule execution.
Best PracticesL51-L74Best practices for designing, tuning, and operating Microsoft Sentinel: automation, playbooks, KQL hunting, analytics rules, UEBA, ASIM, watchlists, SOC metrics, and solution quality.
Decision MakingL75-L118Guidance for planning Sentinel deployments, costs, data tiers, and connectors, plus detailed strategies to migrate from legacy SIEMs (Splunk, QRadar, ArcSight) and optimize detections and automation.
Architecture & Design PatternsL119-L130Designing Microsoft Sentinel architectures: workspace/tenant layouts, SIEM patterns, BCDR/resiliency, data lake/graph designs, and coexisting with or migrating from other SIEMs.
Limits & QuotasL131-L143Limits, quotas, pricing, and availability of Sentinel features (rules, data lake, MCP), plus constraints and safe management of search jobs and watchlists, and removal implications.
SecurityL144-L163Configuring secure access, permissions, encryption, and RBAC for Microsoft Sentinel, including playbooks, data lake, storage connectors, SAP integration, and automated attack disruption across clouds.
ConfigurationL164-L298Configuring Microsoft Sentinel: data connectors and ASIM schemas, analytics rules, automation/playbooks, TI and SAP integrations, data lake jobs, health/auditing, and solution/workbook setup.
Integrations & Coding PatternsL299-L344Patterns and APIs for integrating Sentinel with logs, threat intel, MCP/AI tools, Logic Apps playbooks, data lake, connectors, and external platforms like AWS, Entra ID, Purview.
DeploymentL345-L358Deploying and customizing Microsoft Sentinel content and solutions (rules, automation, notebooks, SAP, Copilot agents) via CI/CD, ARM templates, data lakes, and hybrid/on-prem onboarding.

Troubleshooting

TopicURL
Troubleshoot AWS S3 log ingestion connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/aws-s3-troubleshoot
Troubleshoot Microsoft Sentinel Azure Storage Blob connector issueshttps://learn.microsoft.com/en-us/azure/sentinel/azure-storage-blob-connector-troubleshoot
Troubleshoot Syslog and CEF AMA connectors in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-troubleshooting
Troubleshoot KQL queries and jobs in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-troubleshoot
Resolve common Jupyter notebook errors in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebooks-troubleshooting
Best practices and troubleshooting for Sentinel MCP toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/troubleshoot-sentinel-mcp
Troubleshoot Microsoft Sentinel solution issueshttps://learn.microsoft.com/en-us/azure/sentinel/isv/troubleshoot-sentinel-solutions
Monitor and troubleshoot Sentinel scheduled analytics rule executionhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-optimize-analytics-rule-execution
Troubleshoot Sentinel agentless SAP data connector issueshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-deploy-troubleshoot
Troubleshoot Microsoft Sentinel analytics rule issueshttps://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules

Best Practices

TopicURL
Design Microsoft Sentinel automation rules for SOARhttps://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules
Apply recommended Microsoft Sentinel playbook templates and use caseshttps://learn.microsoft.com/en-us/azure/sentinel/automation/playbook-recommendations
Apply best practices for Microsoft Sentinel workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/best-practices
Apply Sentinel-specific best practices for data collectionhttps://learn.microsoft.com/en-us/azure/sentinel/best-practices-data
Bring custom machine learning models into Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/bring-your-own-ml
Apply sample KQL queries for Sentinel threat huntinghttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-sample-queries
Fine-tune Microsoft Sentinel analytics rule detectionshttps://learn.microsoft.com/en-us/azure/sentinel/detection-tuning
Resolve false positives in Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/false-positives
Handle ingestion delay in Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/ingestion-delay
Use UEBA data to investigate Sentinel incidentshttps://learn.microsoft.com/en-us/azure/sentinel/investigate-with-ueba
Develop and deploy ASIM parsers for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/normalization-develop-parsers
Apply quality guidelines to Sentinel platform solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/platform-solution-quality-guidance
Apply quality guidelines to Sentinel SIEM solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-siem-solution-quality-guidance
Use Sentinel incident metrics to manage SOC performancehttps://learn.microsoft.com/en-us/azure/sentinel/manage-soc-with-incident-metrics
Apply operational best practices for Microsoft Sentinel SOCshttps://learn.microsoft.com/en-us/azure/sentinel/ops-guide
Manage deprecated Microsoft Sentinel solutions lifecyclehttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution-deprecation
Use customizable anomaly detection to find threatshttps://learn.microsoft.com/en-us/azure/sentinel/soc-ml-anomalies
Apply SOC optimization recommendations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-access
Apply Microsoft Sentinel watchlists effectivelyhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists
Manage incident tasks in Sentinel investigationshttps://learn.microsoft.com/en-us/azure/sentinel/work-with-tasks

Decision Making

TopicURL
Plan and execute Sentinel migration from MMA to AMAhttps://learn.microsoft.com/en-us/azure/sentinel/ama-migrate
Decide and migrate Sentinel alert-trigger playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/migrate-playbooks-to-automation-rules
Decide when to use the Microsoft Sentinel data lake tierhttps://learn.microsoft.com/en-us/azure/sentinel/basic-logs-use-cases
Plan and estimate Microsoft Sentinel billing costshttps://learn.microsoft.com/en-us/azure/sentinel/billing
Analyze and optimize Microsoft Sentinel costshttps://learn.microsoft.com/en-us/azure/sentinel/billing-monitor-costs
Choose and optimize Sentinel pre-purchase cost planshttps://learn.microsoft.com/en-us/azure/sentinel/billing-pre-purchase-plan
Reduce and optimize Microsoft Sentinel costshttps://learn.microsoft.com/en-us/azure/sentinel/billing-reduce-costs
Choose and configure Cisco Secure Firewall connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/cisco-ftd-firewall
Choose between Sentinel analytics rules and Defender custom detectionshttps://learn.microsoft.com/en-us/azure/sentinel/compare-analytics-rules-custom-detections
Assess Sentinel connector support across cloudshttps://learn.microsoft.com/en-us/azure/sentinel/data-type-cloud-support
Choose between KQL jobs, summary rules, and search jobs in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs-summary-rules-search-jobs
Choose which logs to ingest into Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-log-ingestion-guidance
Choose detection lifecycle management options in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/detection-lifecycle-management-recommendations
Enroll workspaces in Sentinel simplified pricing tiershttps://learn.microsoft.com/en-us/azure/sentinel/enroll-simplified-pricing-tier
Select Microsoft Sentinel features by Azure cloudhttps://learn.microsoft.com/en-us/azure/sentinel/feature-availability
Plan Microsoft Sentinel deployment for data residencyhttps://learn.microsoft.com/en-us/azure/sentinel/geographical-availability-data-residency
Choose Sentinel platform components for ISV solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/which-platform-components-to-build
Choose Microsoft Sentinel log retention tiershttps://learn.microsoft.com/en-us/azure/sentinel/log-plans
Plan Sentinel data tiers and retention strategyhttps://learn.microsoft.com/en-us/azure/sentinel/manage-data-overview
Determine Defender XDR data type support across GCC clouds in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-cloud-support
Decide how to integrate Microsoft Defender XDR with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration
Plan Microsoft Sentinel use in Microsoft Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-sentinel-defender-portal
Plan migration from legacy SIEM to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration
Migrate ArcSight SOAR automation to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-automation
Plan migration of ArcSight rules to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-detection-rules
Export ArcSight historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-historical-data
Convert legacy SIEM dashboards to Sentinel workbookshttps://learn.microsoft.com/en-us/azure/sentinel/migration-convert-dashboards
Ingest exported SIEM data into Sentinel target platformshttps://learn.microsoft.com/en-us/azure/sentinel/migration-export-ingest
Choose target platform for Sentinel historical datahttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-target-platform
Select data ingestion tools for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-tool
Migrate QRadar SOAR automation to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-automation
Plan migration of QRadar rules to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-detection-rules
Export QRadar historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-historical-data
Migrate Splunk SOAR automation to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-automation
Migrate Splunk detection rules to Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-detection-rules
Export Splunk historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-historical-data
Prioritize Microsoft Sentinel data connectors strategicallyhttps://learn.microsoft.com/en-us/azure/sentinel/prioritize-data-connectors
Migrate from Sentinel SAP agent to agentless connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-agent-migrate
Use SIEM migration tool for Sentinel detectionshttps://learn.microsoft.com/en-us/azure/sentinel/siem-migration
Use Sentinel SOC optimization reference recommendationshttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-reference

Architecture & Design Patterns

TopicURL
Design Sentinel BCDR and cross-region resiliencyhttps://learn.microsoft.com/en-us/azure/sentinel/business-continuity-disaster-recovery
Design custom security graphs with Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/custom-graphs-overview
Deploy Sentinel alongside an existing SIEMhttps://learn.microsoft.com/en-us/azure/sentinel/deploy-side-by-side
Design Sentinel across multiple workspaces and tenantshttps://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
Design Sentinel SIEM solution components and patternshttps://learn.microsoft.com/en-us/azure/sentinel/isv/siem-components-to-include
Plan multi-workspace and multi-tenant Sentinel layoutshttps://learn.microsoft.com/en-us/azure/sentinel/prepare-multiple-workspaces
Choose Microsoft Sentinel workspace designs by scenariohttps://learn.microsoft.com/en-us/azure/sentinel/sample-workspace-designs
Configure multi-workspace and tenant architecture in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/use-multiple-workspaces

Limits & Quotas

TopicURL
Configure and understand Sentinel near-real-time ruleshttps://learn.microsoft.com/en-us/azure/sentinel/create-nrt-rules
Microsoft Sentinel data lake service limits referencehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-service-limits
Microsoft Sentinel MCP pricing and usage limitshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-billing
Understand ASIM known issues and limitations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-known-issues
Understand implications of removing Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/offboard-implications
Use Sentinel search jobs for large data setshttps://learn.microsoft.com/en-us/azure/sentinel/search-jobs
Review Microsoft Sentinel service limits and quotashttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-service-limits
Create and upload watchlists in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-create
Manage and update Sentinel watchlists safelyhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-manage

Security

TopicURL
Configure Sentinel playbook authentication and permissionshttps://learn.microsoft.com/en-us/azure/sentinel/automation/authenticate-playbooks-to-sentinel
Restrict access to Sentinel Standard playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/define-playbook-access-restrictions
Enable automated attack disruption actions on AWShttps://learn.microsoft.com/en-us/azure/sentinel/aws-disruption
Configure customer-managed keys for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/customer-managed-keys
Audit Sentinel data lake and graph activities in Purviewhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/auditing-lake-activities
Meet prerequisites to onboard Sentinel data lake and graphhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboarding
Use Sentinel MCP tools in Azure AI Foundryhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-azure-ai-foundry
Connect Sentinel MCP tools in Copilot Studiohttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-copilot-studio
Secure Sentinel Azure Storage blob connectors with NSPhttps://learn.microsoft.com/en-us/azure/sentinel/enable-storage-network-security
Protect MSSP intellectual property in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/mssp-protect-intellectual-property
Configure resource-context RBAC for Sentinel data accesshttps://learn.microsoft.com/en-us/azure/sentinel/resource-context-rbac
Configure Microsoft Sentinel roles and permissionshttps://learn.microsoft.com/en-us/azure/sentinel/roles
Prepare SAP security settings for Sentinel connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/preparing-sap
Assign required ABAP authorizations for Sentinel SAP userhttps://learn.microsoft.com/en-us/azure/sentinel/sap/required-abap-authorizations
Use Sentinel built-in SAP security contenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-security-content
Monitor SAP security parameters for suspicious changeshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-suspicious-configuration-security-parameters

Configuration

TopicURL
Add incident entities as threat indicators in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/add-entity-to-threat-intelligence
Use Sentinel ML anomaly types for detectionhttps://learn.microsoft.com/en-us/azure/sentinel/anomalies-reference
Create Data Collection Rules for Sentinel using API exampleshttps://learn.microsoft.com/en-us/azure/sentinel/api-dcr-reference
Audit Microsoft Sentinel queries and workspace activitieshttps://learn.microsoft.com/en-us/azure/sentinel/audit-sentinel-data
Use SentinelAudit tables for user activity auditinghttps://learn.microsoft.com/en-us/azure/sentinel/audit-table-reference
Configure Microsoft Sentinel automation rule properties and conditionshttps://learn.microsoft.com/en-us/azure/sentinel/automation-rule-reference
Configure Sentinel playbooks for automated threat responsehttps://learn.microsoft.com/en-us/azure/sentinel/automation/automate-responses-with-playbooks
Deploy Business Apps Sentinel solution for Power Platformhttps://learn.microsoft.com/en-us/azure/sentinel/business-applications/deploy-power-platform-solution
Map CEF keys to Microsoft Sentinel CommonSecurityLog fieldshttps://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping
Understand Syslog and CEF AMA connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-overview
Configure Sentinel Security Events for anomalous RDP detectionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-connector-login-detection
Configure ingestion-time data transformation in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/configure-data-transformation
Configure Fusion multistage attack detection rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules
Connect AWS service logs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws
Ingest AWS EKS audit logs from S3 into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-eks
Ingest AWS WAF logs from S3 into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-s3-waf
Connect Azure Virtual Desktop telemetry to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-virtual-desktop
Configure Sentinel connectors for Azure and Microsoft serviceshttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-windows-microsoft-services
Configure syslog and CEF ingestion via AMA to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog-ama
Collect custom text logs via AMA into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs-ama
Ingest Microsoft Defender for Cloud alerts into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-defender-for-cloud
Stream Windows DNS logs to Sentinel with AMAhttps://learn.microsoft.com/en-us/azure/sentinel/connect-dns-ama
Ingest Google Cloud Platform logs into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-google-cloud-platform
Configure Logstash output with Sentinel DCR-based APIhttps://learn.microsoft.com/en-us/azure/sentinel/connect-logstash-data-connection-rules
Enable Defender Threat Intelligence data connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-mdti-data-connector
Stream Microsoft Defender XDR data into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender
Stream Purview Information Protection data to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-purview
Configure API-based Microsoft Sentinel data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-api-based
Configure diagnostic settings-based Sentinel connectionshttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-diagnostic-setting-based
Configure Windows agent-based Sentinel data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-windows-based
Configure scheduled analytics rules from templates in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rule-from-template
Configure custom scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rules
Configure Sentinel incident creation from connected alertshttps://learn.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts
Customize Microsoft Sentinel alert properties from querieshttps://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details
Customize entity timeline activities in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/customize-entity-activities
Configure Azure Storage Blob CCF data connector ruleshttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-azure-storage
Configure GCP Codeless Connector Framework data connection ruleshttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-gcp
Configure RestApiPoller data connector and rules JSONhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-connection-rules-reference
Define Codeless Connector Framework data connector UI JSONhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-ui-definitions-reference
Configure custom data ingestion and transformation for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/data-transformation
Use asset data table mappings in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/asset-data-tables
Create and manage custom graphs in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-custom-graphs
Build deep-link URLs for Sentinel graph querieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-deep-links-graph-queries
Configure federated data connectors in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/data-federation-setup
Create and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Configure and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Configure and run KQL queries in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries
Configure and schedule Sentinel notebook jobs in VS Codehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-jobs
Configure Sentinel data lake connectors and retentionhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-connectors
Create and configure custom Sentinel MCP tools from KQLhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-create-custom-tool
Configure Microsoft Sentinel MCP server for AI querieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started
Use DNS AMA connector fields and normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/dns-ama-fields
Deploy Sentinel Business Apps solution for D365 Financehttps://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/deploy-dynamics-365-finance-operations-solution
Enable auditing and health monitoring for Sentinel resourceshttps://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring
Reference Microsoft Sentinel entity types and identifiershttps://learn.microsoft.com/en-us/azure/sentinel/entities-reference
Review Fusion-detected multistage attack scenarios in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/fusion-scenario-reference
Configure and interpret Sentinel auditing and health monitoringhttps://learn.microsoft.com/en-us/azure/sentinel/health-audit
Use SentinelHealth table for SIEM health monitoringhttps://learn.microsoft.com/en-us/azure/sentinel/health-table-reference
Bulk import threat intelligence indicators into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/indicators-bulk-file-import
Configure push-based codeless connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/create-push-codeless-connector
Build and publish Sentinel custom graph solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/develop-custom-graph-platform-solutions
Develop Jupyter notebook analytics for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/develop-notebook-platform-solutions
Ingest sample telemetry into Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/isv/ingest-sample-data
Configure analytics rules for Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-analytic-rules-creation
Onboard tenants to the Microsoft Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-data-lake-onboarding
Author hunting queries for Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-hunting-rules-creation
Define and publish Sentinel parsers as Kusto functionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-parsers-creation
Create and configure Sentinel summary ruleshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-summary-rules-creation
Build and configure Sentinel workbooks for solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-workbook-creation
Manage template versions for Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/manage-analytics-rule-templates
Configure Sentinel table tiers and retention settingshttps://learn.microsoft.com/en-us/azure/sentinel/manage-table-tiers-retention
Configure entity mappings in Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities
Use Microsoft Purview Information Protection audit record types in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-purview-record-types-activities
Configure Defender alert grouping to match Sentinel incidentshttps://learn.microsoft.com/en-us/azure/sentinel/migrate-sentinel-incident-creation-rules-alert-grouping
View and manage MITRE ATT&CK coverage in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/mitre-coverage
Audit and monitor Sentinel analytics rule healthhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-analytics-rule-integrity
Monitor Sentinel automation rules and playbook healthhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-automation-health
Monitor Sentinel data connector health with workbookshttps://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health
Monitor SAP connector health and performance in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-sap-system-health
Onboard and manage multiple Sentinel tenants via Lighthousehttps://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers
Configure multi-workspace incident views in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/multiple-workspace-view
Configure near-real-time analytics rules for fast detectionhttps://learn.microsoft.com/en-us/azure/sentinel/near-real-time-rules
Manage workspace-deployed ASIM parsers in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-about-workspace-parsers
Use ASIM common schema fields in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-common-fields
Implement ASIM Application Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-application
Implement ASIM Device Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-device
Implement ASIM User Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-user
Convert Sentinel analytics rules to ASIM schemashttps://learn.microsoft.com/en-us/azure/sentinel/normalization-modify-content
Map AI agent telemetry to ASIM Agent schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-agent
Normalize security alerts with ASIM Alert schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-alert
Use ASIM Asset Entity schema in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-asset
Map audit trail logs to ASIM Audit schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-audit
Normalize authentication logs with ASIM schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-authentication
Map DHCP server events to ASIM DHCP schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dhcp
Normalize DNS logs using ASIM DNS schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dns
Map file activity logs to ASIM File Event schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-file-event
Normalize network sessions with ASIM Network schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-network
Map process activity to ASIM Process Event schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-process-event
Normalize Windows registry events with ASIM schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-registry-event
Map user management activity to ASIM schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-user-management
Use legacy Microsoft Sentinel network normalization schema v0.1https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-v1
Normalize web traffic with ASIM Web Session schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-web
Configure Microsoft Sentinel Jupyter notebooks with MSTICPyhttps://learn.microsoft.com/en-us/azure/sentinel/notebook-get-started
Configure MSTICPy and Jupyter notebooks for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/notebooks-msticpy-advanced
Restore and manage archived Sentinel log datahttps://learn.microsoft.com/en-us/azure/sentinel/restore
Configure SAP HANA audit log collection in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/collect-sap-hana-audit-logs
Configure agentless SAP data connector for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-data-connector-agentless
Configure SAP security content and detections in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deployment-solution-configuration
Use SAP Sentinel workspace functions for security analysishttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-function-reference
Reference SAP Sentinel logs, tables, and schemashttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-log-reference
Stop SAP data collection with Sentinel agentless connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/stop-collection
Configure SAP connector polling and DCR in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/update-sap-connector-data-collection-rule
Configure scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/scheduled-rules-overview
Use Microsoft Sentinel security alert schema fieldshttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema
Configure Sentinel alert schemas for XDR connectorshttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema-differences
Understand Sentinel out-of-the-box content centralizationhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-content-centralize
Configure Sentinel Zero Trust (TIC 3.0) monitoring solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution
Set up Azure Storage Blob connector for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/setup-azure-storage-connector
Configure and use Sentinel summary ruleshttps://learn.microsoft.com/en-us/azure/sentinel/summary-rules
Configure custom details in Microsoft Sentinel alertshttps://learn.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts
Configure threat intelligence feed integrations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/threat-intelligence-integration
Configure filter and split data transformations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/transformation-filter-split
Reference UEBA entity enrichments and data sourceshttps://learn.microsoft.com/en-us/azure/sentinel/ueba-reference
Configure Custom Logs via AMA for specific applicationshttps://learn.microsoft.com/en-us/azure/sentinel/unified-connector-custom-device
Enable matching analytics with Microsoft threat intelligencehttps://learn.microsoft.com/en-us/azure/sentinel/use-matching-analytics-to-detect-threats
Use Microsoft Sentinel built-in watchlist schemashttps://learn.microsoft.com/en-us/azure/sentinel/watchlist-schemas
Use watchlists in KQL queries and detection ruleshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-queries
Select Windows security event sets for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/windows-security-event-id-reference
Query STIX objects and migrate to new TI tables in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-stix-objects-indicators
Manage and visualize threat intelligence in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-threat-indicators
Provision and operate Sentinel workspace manager at scalehttps://learn.microsoft.com/en-us/azure/sentinel/workspace-manager

Integrations & Coding Patterns

TopicURL
Use automation integrations in Microsoft Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/integrations
Leverage Azure Logic Apps workflows for Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/logic-apps-playbooks
Use Microsoft Sentinel playbook triggers and actions via Logic Appshttps://learn.microsoft.com/en-us/azure/sentinel/automation/playbook-triggers-actions
Configure AWS environment to send logs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-configure-environment
Connect Microsoft Entra ID logs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory
Integrate Microsoft Sentinel with data sources using Azure Functionshttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-functions-template
Integrate STIX/TAXII threat feeds and exports with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii
Connect threat intelligence platforms to Sentinel (legacy connector)https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-tip
Integrate TIP feeds with Sentinel via upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api
Author custom graphs with AI in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-graphs-with-ai
Query Sentinel graphs using GQL syntax and operatorshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/gql-reference-for-sentinel-custom-graph
Call Sentinel custom graph REST APIs from clientshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/graph-rest-api
Query and visualize custom graphs in Sentinel graphhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/graph-visualization
Use REST APIs to run KQL on Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api
Query Sentinel data lake from Jupyter notebookshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-examples
Use the Sentinel graph provider APIhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-graph-provider-reference
Use Sentinel MCP agent creation toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-agent-creation-tool
Enable Sentinel MCP connector in ChatGPT or Claudehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-chatgpt-claude-connector
Use Sentinel MCP data exploration toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-data-exploration-tool
Build Logic Apps with Sentinel MCP entity analyzerhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-logic-apps
Add Sentinel MCP tools to Security Copilothttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-security-copilot
Integrate Sentinel MCP tools with VS Codehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-visual-studio-code
Use MicrosoftSentinelProvider class to access data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-provider-class-reference
Query and use federated data sources in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/using-data-federation
Enrich Sentinel entities with geolocation data using REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/geolocation-data-api
Manage Sentinel hunting queries via Log Analytics REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/hunting-with-rest-api
Integrate Defender for Cloud incidents into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ingest-defender-for-cloud-incidents
Develop Security Copilot agents with Sentinel datahttps://learn.microsoft.com/en-us/azure/sentinel/isv/build-agent-security-copilot
Build pull codeless connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/create-codeless-connector
Build AI-assisted custom Sentinel data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/isv/create-custom-connector-builder-agent
Implement nested API polling in Sentinel connectorshttps://learn.microsoft.com/en-us/azure/sentinel/isv/custom-connector-nested-api-polling
Implement multi-account Sentinel codeless connector patternshttps://learn.microsoft.com/en-us/azure/sentinel/isv/multi-account-ccf-connector
Create Sentinel playbooks for automated responseshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-playbook-creation
Use ASIM KQL parsers for normalized Sentinel querieshttps://learn.microsoft.com/en-us/azure/sentinel/normalization-about-parsers
Apply ASIM helper functions in KQL querieshttps://learn.microsoft.com/en-us/azure/sentinel/normalization-functions
Integrate Microsoft Purview insights with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/purview-solution
Trigger Sentinel playbooks from investigation entitieshttps://learn.microsoft.com/en-us/azure/sentinel/respond-threats-during-investigation
Call Sentinel SOC optimization recommendations APIhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-api
Import threat intelligence STIX objects into Sentinel via upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/stix-objects-api
Extract non-native incident entities with Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/tutorial-extract-incident-entities
Configure Syslog via AMA for specific applianceshttps://learn.microsoft.com/en-us/azure/sentinel/unified-connector-syslog-device
Use legacy Sentinel upload indicators API for STIX IOCshttps://learn.microsoft.com/en-us/azure/sentinel/upload-indicators-api

Deployment

TopicURL
Set up CI/CD deployments of custom Sentinel contenthttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd
Customize repository-based content deployments in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-deploy
Onboard Azure Stack Hub virtual machines to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-stack
Deploy Sentinel data lake from Microsoft Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboard-defender
Deploy Sentinel analytics rules via ARM templateshttps://learn.microsoft.com/en-us/azure/sentinel/import-export-analytics-rules
Deploy Sentinel automation rules via ARM templateshttps://learn.microsoft.com/en-us/azure/sentinel/import-export-automation-rules
Package and deploy Sentinel graph/notebook solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/package-publish-notebook-graph-solutions
Publish Microsoft Security Copilot agents to storehttps://learn.microsoft.com/en-us/azure/sentinel/isv/publish-agent-to-security-store
Publish Sentinel SIEM solutions via Partner Centerhttps://learn.microsoft.com/en-us/azure/sentinel/isv/publish-sentinel-solutions
Deploy Microsoft Sentinel solution for SAP BTPhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-sap-btp-solution
Prepare Sentinel SAP agentless connector deploymenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/prerequisites-for-deploying-sap-continuous-threat-monitoring
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

CC-BY-4.0

源路径

skills/azure-sentinel

默认分支

main

最新提交

1e593dd

Tree SHA

a074c78