Microsoft Sentinel

Oct 4, 2024

Sentinel Phantom Fields: Understanding and Managing Inaccessible Data

Microsoft has transitioned to a DCR-based log ingestion and manual schema management for tables. Many organizations are adopting this modern approach to parse, filter, and enrich logs during ingestion. While effective, this system can incur unnecessary expenses if not used properly, leading to billable fields that remain inaccessible when querying events. We refer to these […]

Read More
Sentinel Phantom Fields: Understanding and Managing Inaccessible Data
Mar 13, 2024

Defender for Cloud and Defender XDR Connectors in Sentinel

Over the past few weeks, Microsoft Defender for Cloud has received multiple updates. Microsoft has introduced a new tenant-level Defender for Cloud connector, replacing the old subscription-level one. Additionally, they have implemented a new functionality, allowing detections from Defender for Cloud to be integrated into Defender XDR, along with detections from other Defender solutions.  There are […]

Read More
Defender for Cloud and Defender XDR Connectors in Sentinel
Oct 2, 2023

Log Splitting with Data Collection Rules

In a recent article, Microsoft discussed log splitting in Data Collection Rules (DCRs), also known as Multi-Destination Data Collection Rules. Microsoft mentioned a few uses for this capability. I’ve worked with numerous clients in the past who had certain needs that log splitting would have made much simpler to fulfill. In this blog post, I’ll […]

Read More
Log Splitting with Data Collection Rules
Page 1 of 1
Back to top
Close