Forum Discussion

AutomationMan's avatar
AutomationMan
Copper Contributor
Aug 18, 2020

Writing rules for legacy server feeds

Hi, I'm new to Sentinel with my only real experience being the MS Sentinel Ninja training. I have a list of events from an existing SIEM that I need to replicate in Sentinel using data coming from...
  • Thijs Lecomte's avatar
    Thijs Lecomte
    Aug 24, 2020
    Hi

    For the schedules, I would do it another way
    You could write a script which runs a query for you and then shoots an email.
    That is probably the preferred way as you are looking for reporting, not alerting.

    For emails, it's true Logic Apps is the only way. For something simple as email, I agree that it's a bit of a hassle to go through

    Uploading TI's is also possible through API, which might be easier for a few quick tests

Resources