Home

Time Series analysis and visualization in Azure Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-680863%22%20slang%3D%22en-US%22%3ETime%20Series%20analysis%20and%20visualization%20in%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-680863%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20posted%20couple%20of%20blogs%20around%20Time%20Series%20analysis%20and%20visualization%20on%20security%20event%20log%20data%20sources%20in%20Azure%20Sentinel%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBlog%201%3A%20Introduction%20to%20Time%20Series%2C%20Step%20by%20step%20guide%20on%20compiling%20queries%2C%20configure%20alerts%20and%20investigate%20the%20results.%3C%2FP%3E%0A%3CP%3EData%20Source%20%3A%20Windows%20Event%20Log%20-%20Process%20Execution%20Data%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FLooking-for-unknown-anomalies-what-is-normal-Time-Series%2Fba-p%2F555052%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FLooking-for-unknown-anomalies-what-is-normal-Time-Series%2Fba-p%2F555052%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBlog%202%3A%26nbsp%3B%20Visualization%20and%20interpreting%20Time%20Series%20Data.%3C%2FP%3E%0A%3CP%3EData%20Source-%20Palo%20Alto%20Network%20Traffic%20Logs%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FTime-Series-visualization-of-Palo-Alto-logs-to-detect-data%2Fba-p%2F666344%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FTime-Series-visualization-of-Palo-Alto-logs-to-detect-data%2Fba-p%2F666344%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20always%2C%20Feedbacks%20or%20questions%20are%20welcome.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Ashwin_Patil
Microsoft

I have posted couple of blogs around Time Series analysis and visualization on security event log data sources in Azure Sentinel

 

Blog 1: Introduction to Time Series, Step by step guide on compiling queries, configure alerts and investigate the results.

Data Source : Windows Event Log - Process Execution Data

https://techcommunity.microsoft.com/t5/Azure-Sentinel/Looking-for-unknown-anomalies-what-is-normal-T...

 

Blog 2:  Visualization and interpreting Time Series Data.

Data Source- Palo Alto Network Traffic Logs

https://techcommunity.microsoft.com/t5/Azure-Sentinel/Time-Series-visualization-of-Palo-Alto-logs-to...

 

As always, Feedbacks or questions are welcome.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies