Forum Discussion

TKDJoe's avatar
TKDJoe
Copper Contributor
Apr 10, 2020
Solved

Azure Sentinel Walk-through Lab Training

I've just begun learning Azure Sentinel, all the MS Docs, and 3rd-party training videos utilize pre-configured materials to *demonstrate* creating alerts which generate incidents, doing hunting scena...
  • GabrielNecula's avatar
    Apr 10, 2020

    TKDJoe 

     

    My general advice is familiarize yourself with the interface first. Familiarize yourself with what connectors come built in Sentinel and you can take advantage of in the beginning. For everything else you re going to have to do it by hand.

     

    For learning Kusto, there's a good course on Pluralsight. There's also the way of taking pre build analytics rule and trying to understand Kusto from those, but they are quite complex and it would not be easy. However, Kusto is as simple as it gets. You will find it really easy.

     

    Do not delve into Notebooks just yet as those are quite complex.

    Playbooks / Logic Apps are quite intensive to troubleshoot in my small experience, but can help you automate your stuff.

Resources