search
Get Started
search
Azure Sentinel (Microsoft Sentinel) - Azure Monitor
zoom_in Click to enlarge

Azure Sentinel (Microsoft Sentinel)

description Azure Sentinel (Microsoft Sentinel) Overview

This is Azure's powerful, cloud-native Security Information and Event Management (SIEM) solution. It aggregates security data from virtually every sourceAzure resources, on-premises firewalls, and third-party SaaS toolsinto one pane of glass. It uses advanced analytics and built-in playbooks (SOAR) to automate incident response, drastically reducing Mean Time To Respond (MTTR).

help Azure Sentinel (Microsoft Sentinel) FAQ

What was Azure Sentinel renamed to?

Azure Sentinel was renamed Microsoft Sentinel in 2021. The product remains Microsoft's cloud-native SIEM and security orchestration platform.

What does Microsoft Sentinel collect security data from?

Microsoft Sentinel can aggregate signals from Azure services, on-premises firewalls, endpoint tools, and third-party SaaS systems. Its purpose is to bring those sources into a common investigation and detection workspace.

Does Microsoft Sentinel replace Microsoft Defender?

No, Microsoft Sentinel and Microsoft Defender serve different roles but can work together. Defender products provide security signals, while Sentinel correlates those signals with data from Azure, networks, and external systems.

What query language is used in Microsoft Sentinel?

Microsoft Sentinel uses Kusto Query Language, commonly called KQL, for searching and analyzing security data. The data is typically stored and queried through an Azure Log Analytics workspace.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare