Home

No data was found

%3CLINGO-SUB%20id%3D%22lingo-sub-481878%22%20slang%3D%22en-US%22%3ENo%20data%20was%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-481878%22%20slang%3D%22en-US%22%3E%3CP%3EI%20activated%20sentinel%20yesterday%20but%20get%20no%20data%20was%20found%20like%20in%20the%20image%20below.%20Is%20there%20anything%20I%20have%20missed%3F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110137i1CB8DD2FBF70FC66%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22sentinelerror.PNG%22%20title%3D%22sentinelerror.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-482590%22%20slang%3D%22en-US%22%3ERe%3A%20No%20data%20was%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-482590%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F326250%22%20target%3D%22_blank%22%3E%40planet4%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20don't%20mind%20creating%20your%20own%20list%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3EW3CIISLog%0A%7C%20extend%20countrycode%20%3D%20case(RemoteIPCountry%20%3D%3D%20%22UnitedStates%22%2C%22US%22%2C%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20RemoteIPCountry%20%3D%3D%20%22United%20Kingdom%22%2C%22UK%22%2C%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2F%2F%20add%20others%20here%0A%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%22Unknown%20Country%22)%0A%7C%20where%20isnotempty(RemoteIPCountry)%0A%7C%20project%20RemoteIPCountry%2C%20countrycode%3C%2FPRE%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-482533%22%20slang%3D%22en-US%22%3ERe%3A%20No%20data%20was%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-482533%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40Clive%20Watson%3C%2FA%3EOk%2C%20Thanks%2C%20Have%20made%20some%20progress%20with%20the%20IIS%20log.%20I%20am%20trying%20to%20get%20this%20into%20the%20Grafana%20Worldmap%20but%20I%20suppose%20this%20is%20another%20issute.%20Having%20problems%20with%20country%20codes%20and%20that%20IIS%20writes%20the%20full%20country%20instead%20of%20US%20or%20SE.%20Will%20try%20more%20and%20thanks%20for%20your%20response.%3C%2FP%3E%3CBLOCKQUOTE%3E%3CHR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40Clive%20Watson%3C%2FA%3E%26nbsp%3Bwrote%3A%3CBR%20%2F%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F326250%22%20target%3D%22_blank%22%3E%40planet4%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20%5BData%20Connectors%5D%20have%20you%20added%3F%26nbsp%3B%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-data-sources%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-data-sources%3C%2FA%3E%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Cases%20(top%20right)%20needs%20you%20to%20have%20created%20an%20Alert%20entry%20in%20%5BAnalytics%5D%20-%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-get-visibility%23create-new-detections%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-get-visibility%23create-new-detections%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20The%20map%20(middle%20bottom)%20needs%20data%20from%20at%20least%20one%20of%20these%20data%20sources%3A%3C%2FP%3E%3CP%3E-%20%3CSTRONG%3EW3CIISLog%26nbsp%3B%20%26nbsp%3B%3C%2FSTRONG%3E(enable%20in%20Log%20Analytics)%3C%2FP%3E%3CP%3E-%20%3CSTRONG%3EWiredata%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3C%2FSTRONG%3E(enable%20in%20Log%20Analytics)%3C%2FP%3E%3CP%3E-%20%3CSTRONG%3EWindowsFirewall%26nbsp%3B%3C%2FSTRONG%3E%20(Sentinel%20Connector)%3C%2FP%3E%3CP%3E-%20%3CSTRONG%3ECommonSecurityLog%3C%2FSTRONG%3E%20(Sentinel%20Connector)%3C%2FP%3E%3CP%3E-%20%3CSTRONG%3EVMConnection%3C%2FSTRONG%3E%20(Enable%20in%20Log%20Analytics)%3C%2FP%3E%3CP%3Eor%20%3CSTRONG%3EDnsEvents%3C%2FSTRONG%3E%20(Sentinel%20Connector)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20see%20your%20Data%20in%20your%20%3CEM%3Eworkspace%3C%2FEM%3E%20from%20the%20%3CEM%3ESchema%3C%2FEM%3E%20items%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20618px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110172i60FDEB8907814D9F%2Fimage-dimensions%2F618x603%3Fv%3D1.0%22%20width%3D%22618%22%20height%3D%22603%22%20alt%3D%22Annotation%202019-04-24%20163403.png%22%20title%3D%22Annotation%202019-04-24%20163403.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CHR%20%2F%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-482067%22%20slang%3D%22en-US%22%3ERe%3A%20No%20data%20was%20found%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-482067%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F326250%22%20target%3D%22_blank%22%3E%40planet4%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhat%20%5BData%20Connectors%5D%20have%20you%20added%3F%26nbsp%3B%20%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-data-sources%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-data-sources%3C%2FA%3E%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E1.%20Cases%20(top%20right)%20needs%20you%20to%20have%20created%20an%20Alert%20entry%20in%20%5BAnalytics%5D%20-%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-get-visibility%23create-new-detections%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-get-visibility%23create-new-detections%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E2.%20The%20map%20(middle%20bottom)%20needs%20data%20from%20at%20least%20one%20of%20these%20data%20sources%3A%3C%2FP%3E%0A%3CP%3E-%20%3CSTRONG%3EW3CIISLog%26nbsp%3B%20%26nbsp%3B%3C%2FSTRONG%3E(enable%20in%20Log%20Analytics)%3C%2FP%3E%0A%3CP%3E-%20%3CSTRONG%3EWiredata%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3C%2FSTRONG%3E(enable%20in%20Log%20Analytics)%3C%2FP%3E%0A%3CP%3E-%20%3CSTRONG%3EWindowsFirewall%26nbsp%3B%3C%2FSTRONG%3E%20(Sentinel%20Connector)%3C%2FP%3E%0A%3CP%3E-%20%3CSTRONG%3ECommonSecurityLog%3C%2FSTRONG%3E%20(Sentinel%20Connector)%3C%2FP%3E%0A%3CP%3E-%20%3CSTRONG%3EVMConnection%3C%2FSTRONG%3E%20(Enable%20in%20Log%20Analytics)%3C%2FP%3E%0A%3CP%3Eor%20%3CSTRONG%3EDnsEvents%3C%2FSTRONG%3E%20(Sentinel%20Connector)%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20see%20your%20Data%20in%20your%20%3CEM%3Eworkspace%3C%2FEM%3E%20from%20the%20%3CEM%3ESchema%3C%2FEM%3E%20items%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20618px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F110172i60FDEB8907814D9F%2Fimage-dimensions%2F618x603%3Fv%3D1.0%22%20width%3D%22618%22%20height%3D%22603%22%20alt%3D%22Annotation%202019-04-24%20163403.png%22%20title%3D%22Annotation%202019-04-24%20163403.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
planet4
New Contributor

I activated sentinel yesterday but get no data was found like in the image below. Is there anything I have missed?

sentinelerror.PNG

 

3 Replies

@planet4 

 

What [Data Connectors] have you added? 
https://docs.microsoft.com/en-us/azure/sentinel/connect-data-sources  

 

1. Cases (top right) needs you to have created an Alert entry in [Analytics] - see https://docs.microsoft.com/en-us/azure/sentinel/quickstart-get-visibility#create-new-detections

 

2. The map (middle bottom) needs data from at least one of these data sources:

- W3CIISLog   (enable in Log Analytics)

- Wiredata      (enable in Log Analytics)

- WindowsFirewall  (Sentinel Connector)

- CommonSecurityLog (Sentinel Connector)

- VMConnection (Enable in Log Analytics)

or DnsEvents (Sentinel Connector)

 

You can see your Data in your workspace from the Schema items

Annotation 2019-04-24 163403.png

 

 

 

@Clive WatsonOk, Thanks, Have made some progress with the IIS log. I am trying to get this into the Grafana Worldmap but I suppose this is another issute. Having problems with country codes and that IIS writes the full country instead of US or SE. Will try more and thanks for your response.


@Clive Watson wrote:

@planet4 

 

What [Data Connectors] have you added? 
https://docs.microsoft.com/en-us/azure/sentinel/connect-data-sources  

 

1. Cases (top right) needs you to have created an Alert entry in [Analytics] - see https://docs.microsoft.com/en-us/azure/sentinel/quickstart-get-visibility#create-new-detections

 

2. The map (middle bottom) needs data from at least one of these data sources:

- W3CIISLog   (enable in Log Analytics)

- Wiredata      (enable in Log Analytics)

- WindowsFirewall  (Sentinel Connector)

- CommonSecurityLog (Sentinel Connector)

- VMConnection (Enable in Log Analytics)

or DnsEvents (Sentinel Connector)

 

You can see your Data in your workspace from the Schema items

Annotation 2019-04-24 163403.png

 

 

 




@planet4 

 

If you don't mind creating your own list?

 

W3CIISLog
| extend countrycode = case(RemoteIPCountry == "UnitedStates","US",
                            RemoteIPCountry == "United Kingdom","UK",
                            // add others here
                             "Unknown Country")
| where isnotempty(RemoteIPCountry)
| project RemoteIPCountry, countrycode
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies