Forum Discussion
Jesto001
Jun 16, 2022Copper Contributor
Azure Sentinel Side by Side with QRadar
Hi,
quick question:
in the "Event Filter" on Qradar we add:
vendorInformation/provider eq 'Azure Sentinel'
to get Sentinel events but is it possible to include another azure instances such as Cloud App, Identity, etc?
I mean, like:
provider eq 'Azure Sentinel, MCAS, IPS'
thank you
2 Replies
- Clive_WatsonBronze Contributoralso
SecurityAlert
| where ProductName in ("Microsoft Cloud App Security","product A","product B")