description Azure Sentinel (Microsoft Sentinel) Overview
This is Azure's powerful, cloud-native Security Information and Event Management (SIEM) solution. It aggregates security data from virtually every sourceAzure resources, on-premises firewalls, and third-party SaaS toolsinto one pane of glass. It uses advanced analytics and built-in playbooks (SOAR) to automate incident response, drastically reducing Mean Time To Respond (MTTR).
help Azure Sentinel (Microsoft Sentinel) FAQ
What was Azure Sentinel renamed to?
Azure Sentinel was renamed Microsoft Sentinel in 2021. The product remains Microsoft's cloud-native SIEM and security orchestration platform.
What does Microsoft Sentinel collect security data from?
Microsoft Sentinel can aggregate signals from Azure services, on-premises firewalls, endpoint tools, and third-party SaaS systems. Its purpose is to bring those sources into a common investigation and detection workspace.
Does Microsoft Sentinel replace Microsoft Defender?
No, Microsoft Sentinel and Microsoft Defender serve different roles but can work together. Defender products provide security signals, while Sentinel correlates those signals with data from Azure, networks, and external systems.
What query language is used in Microsoft Sentinel?
Microsoft Sentinel uses Kusto Query Language, commonly called KQL, for searching and analyzing security data. The data is typically stored and queried through an Azure Log Analytics workspace.
explore Explore More
Similar to Azure Sentinel (Microsoft Sentinel)
compare_arrows Compare: Azure Monitor Action Groups See all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.