%3CLINGO-SUB%20id%3D%22lingo-sub-1260578%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1260578%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20awesome%20-%20Thanks%20for%20posting!!!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1260780%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1260780%22%20slang%3D%22en-US%22%3E%3CP%3EAwesome%20Blogpost%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F591947%22%20target%3D%22_blank%22%3E%40Cyb3rWard0g%3C%2FA%3E%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Fhtml%2Fimages%2Femoticons%2Fcool_40x40.gif%22%20alt%3D%22%3Acool%3A%22%20title%3D%22%3Acool%3A%22%20%2F%3E%20Thank%20you%20for%20Sharing%20with%20the%20Community.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1261163%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1261163%22%20slang%3D%22en-US%22%3E%3CP%3EHas%20anyone%20else%20had%20problems%20getting%20their%20sec%20ops%20team%20to%20adopt%20the%20Kusto%20query%20language%3F%20Pointing%20them%20to%20the%20Microsoft%20docs%20does%20not%20help.%20Any%20more%20robust%20training%20out%20there%20around%20Kusto%20and%20most%20common%20queried%20scenarios%3F%20I%20am%20personally%20embracing%20it%20but%20if%20the%20rest%20of%20my%20team%20ignores%20it%20then%20the%20tool%20isn't%20useful.%20They%20seem%20to%20want%20to%20be%20able%20to%20drill%20down%20without%20having%20to%20write%20custom%20queries%20for%20common%20scenarios...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1261589%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1261589%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F591947%22%20target%3D%22_blank%22%3E%40Cyb3rWard0g%3C%2FA%3E%26nbsp%3B%20Hi!%20really%20cool%20stuff.%20I%20could%20not%20find%20the%20ala-python-data-producer.py%20file...%20I%20must%20have%20missed%20something%20here.%20Can%20you%20assist%3F%20thanks%3C%2FP%3E%3CP%3EYaniv.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1261625%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1261625%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F152270%22%20target%3D%22_blank%22%3E%40Yaniv%20Shmulevich%3C%2FA%3E%20%2C%20Yes%20I%20updated%20the%20post%20with%20a%20link%20to%20the%20project%20at%20the%20end%20of%20the%20post%2C%20and%20also%20while%20I%20show%20the%20scripts%20options.%20This%20is%20the%20link%20of%20the%20project%20where%20I%20host%20those%20scripts%20(Proof%20of%20concept)%20%3A%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%3C%2FA%3E%20.%20Thank%20you%20for%20the%20feedback!%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1261823%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1261823%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F591947%22%20target%3D%22_blank%22%3E%40Cyb3rWard0g%3C%2FA%3E%26nbsp%3B%20thanks%2C%20found%20it%20%3A)%3C%2Fimg%3E%20.%20I%20decided%20to%20execute%20the%20ps%20script%20this%20time%20to%20ingest%20data.%20I%20ran%20it%20few%20times%20and%20nothing%20happened.%20I%20debugged%20it%20and%20I%20realized%20that%20it%20never%20reaches%20the%20Post-LogAnalyticsData%20(line187)%20command.%20I%20remarked%20it%20and%20put%20two%20lines%20at%20location%20200%2C201%3A%3C%2FP%3E%3CUL%3E%3CLI%3E%24json_records_converted%20%3D%20%24json_records%20%7C%20ConvertTo-Json%3C%2FLI%3E%3CLI%3EPost-LogAnalyticsData%20-customerId%20%24WorkspaceId%20-sharedKey%20%24WorkspaceSharedKey%20-body%20(%5BSystem.Text.Encoding%5D%3A%3AUTF8.GetBytes(%24json_records_converted))%20-logType%20%24logType%26nbsp%3B%3C%2FLI%3E%3C%2FUL%3E%3CP%3Eand%20it%20succeeded.%20I%20hope%20I%20am%20right%20here.%20anyway%2C%20it%20is%20the%20only%20option%20I%20succeeded%20to%20ingest%20data%20to%20log%20analytics.%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3EYaniv.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1260191%22%20slang%3D%22en-US%22%3EAzure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templates%20%3Arocket%3A%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1260191%22%20slang%3D%22en-US%22%3E%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_0-1585349796021.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180089i1B689199690D227A%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_0-1585349796021.png%22%20alt%3D%22Cyb3rWard0g_0-1585349796021.png%22%20%2F%3E%3C%2FSPAN%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ERecently%2C%20I%20started%20working%20with%20Azure%20Sentinel%2C%20and%20as%20any%20technology%20that%20I%20am%20learning%20about%2C%20I%20decided%20to%20explore%20a%20few%20ways%20to%20deploy%20it.%20I%20got%20a%20grasp%20of%20the%20basic%20architecture%20and%20got%20more%20familiarized%20with%20the%20tool.%20As%20a%20researcher%2C%20I%20also%20like%20to%20simplify%20deployments%20in%20my%20lab%20environment%20and%20usually%20look%20for%20ways%20to%20implement%20the%20infrastructure%20I%20work%20with%20as%20code.%20Often%20times%20I%20find%20myself%20automating%20the%20deployment%20of%20the%20main%20tool%20but%20end%20up%20with%20no%20data%20or%20other%20resources%20to%20play%20with.%20Therefore%2C%20I%20typically%20like%20to%20deploy%20additional%20resources%20to%20generate%20data%20on-the-fly%20as%20well%20as%20to%20consume%20pre-recorded%20datasets.%20Once%20I%20actually%20have%20data%2C%20I%20can%20start%20working.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EIn%20the%20end%2C%20this%20approach%20allows%20me%20to%20also%20share%20the%20process%20with%20others%20in%20the%20community%20in%20a%20more%20practical%20way.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThis%20post%20is%20part%20of%20a%20two-part%20series%20where%20I%20will%20show%20you%20how%20to%20deploy%20your%20own%20Azure%20Sentinel%20solution%20in%20a%20lab%20environment%20via%20Azure%20Resource%20Management%20(ARM)%20templates%20along%20with%20a%20custom%20logs%20ingestion%20pipeline%20to%20consume%20pre-recorded%20datasets%20and%20other%20resources%20for%20research%20purposes.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EIn%20this%20post%2C%20I%20show%20you%20how%20to%20use%20ARM%20templates%20to%20deploy%20an%20Azure%20Sentinel%20solution%20and%20ingest%20pre-recorded%20datasets%20via%20a%20python%20script%2C%20Azure%20Event%20Hubs%20and%20a%20Logstash%20pipeline.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThe%20second%20part%20can%20be%20found%20in%20the%20following%20link%3A%3C%2FP%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EAzure%20Sentinel%20To-Go!%20%E2%80%94%E2%80%8APart%202%3A%20Deploying%20Azure%20Resources%20to%20Explore%20Additional%20Sentinel%E2%80%99s%20Capabilities%20via%20Azure%20Resource%20Manager%20templates%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--1382292939%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%20id%3D%22toc-hId--1382292943%22%3EWhat%20is%20Azure%20Sentinel%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EMicrosoft%20Azure%20Sentinel%20is%20a%20scalable%2C%20cloud-native%2C%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Esecurity%20information%20event%20management%20(SIEM)%3C%2FSTRONG%3E%20and%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Esecurity%20orchestration%20automated%20response%20(SOAR)%3C%2FSTRONG%3E%20solution.%20An%20Azure%20service%20that%20empowers%20organizations%20to%20bring%20disparate%20data%20sources%20from%20resources%20hosted%20both%20on-premises%20and%20in%20multiple%20clouds%20and%20be%20able%20to%20detect%2C%20investigate%20and%20respond%20to%20threats.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EIf%20you%20want%20to%20learn%20more%20about%20Azure%20Sentinel%2C%20I%20would%20recommend%20to%20explore%20this%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2F%22%3EMicrosoft%20Azure%20document%20page%3C%2FA%3E.%20Also%2C%20if%20you%20want%20to%20know%20what%20you%20can%20do%20with%20it%2C%20make%20sure%20you%20read%20the%20articles%20available%20in%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fbg-p%2FAzureSentinelBlog%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%20data-href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fbg-p%2FAzureSentinelBlog%22%3EMicrosoft%20Tech%20Community%20Sentinel%20blog%3C%2FA%3E%20and%20take%20a%20look%20at%20these%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fsecurity-privacy-compliance%2Fsecurity-community-webinars%2Fm-p%2F927888%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%20data-href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fsecurity-privacy-compliance%2Fsecurity-community-webinars%2Fm-p%2F927888%22%3Eawesome%20webinars%3C%2FA%3E.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId-1105219894%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%20id%3D%22toc-hId-1105219890%22%3EDeploying%20Azure%26nbsp%3BSentinel%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ETechnically%2C%20all%20we%20need%20to%20do%20to%20deploy%20an%20Azure%20Sentinel%20solution%20is%3A%3C%2FP%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3ECreate%20a%20Log%20Analytics%20Workspace%3C%2FSTRONG%3E%3A%20Azure%20Sentinel%20leverages%20the%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdesign-logs-deployment%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdesign-logs-deployment%22%3EAzure%20Monitor%20Log%20Analytics%20workspace%3C%2FA%3E%20to%20store%20the%20data%20it%20collects..%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EEnable%20Azure%20Sentinel%3A%20%3C%2FSTRONG%3EThis%20is%20enabled%20on%20the%20top%20of%20the%20workspace.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThat%20basic%20set%20up%20allows%20you%20explore%20all%20the%20main%20features%20of%20Azure%20Sentinel%20as%20well%20as%20preloaded%20out-of-the-box%20resources%20such%20as%20queries%2C%20visualizations%2C%20response%20playbooks%2C%20and%20notebooks.%20You%20could%20also%20upload%20other%20resources%20and%20even%20enable%20data%20connectors%20in%20Sentinel%20via%20code.%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F66621%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%20data-href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F66621%22%3EJavier%20Soriano%3C%2FA%3E%20blogged%20about%20it%20in%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-as-code%2Fba-p%2F1131928%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%20data-href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-as-code%2Fba-p%2F1131928%22%3Ethis%20post%3C%2FA%3E%2C%20and%20it%20is%20a%20great%20reference%20for%20production%20deployments.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOne%20of%20the%20things%20I%20wanted%20to%20do%20different%20for%20this%20post%20was%20execute%20Azure%20Sentinel%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EOn-boarding%3C%2FSTRONG%3E%3C%2FA%3E%20steps%2C%20but%20in%20a%20declarative%20way%20with%20Azure%20Resource%20Manager%20(ARM)%20templates%20without%20having%20to%20run%20Powershell%20commands.%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--702234569%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%20id%3D%22toc-hId--702234573%22%3EAzure%20Resource%20Manager%20(ARM)%20Templates%3F%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CBLOCKQUOTE%20class%3D%22graf%20graf--blockquote%22%3ETo%20implement%20infrastructure%20as%20code%20for%20your%20Azure%20solutions%2C%20use%20Azure%20Resource%20Manager%20templates.%20The%20template%20is%20a%20JavaScript%20Object%20Notation%20(JSON)%20file%20that%20defines%20the%20infrastructure%20and%20configuration%20for%20your%20project.%20The%20template%20uses%20declarative%20syntax%2C%20which%20lets%20you%20state%20what%20you%20intend%20to%20deploy%20without%20having%20to%20write%20the%20sequence%20of%20programming%20commands%20to%20create%20it.%3C%2FBLOCKQUOTE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThe%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%22%3EAzure%20Resource%20Manager%3C%2FA%3E%20is%20the%20deployment%20and%20management%20service%20for%20Azure%20and%20below%20you%20can%20see%20some%20of%20the%20ways%20you%20could%20interact%20with%20it.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_0-1585344767287.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180038i1C36AAC1DE0B112F%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_0-1585344767287.png%22%20alt%3D%22Cyb3rWard0g_0-1585344767287.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20class%3D%22markup--anchor%20markup--figure-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EA%20few%20things%20that%20I%20like%20about%20ARM%20templates%20are%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Eorchestration%3C%2FSTRONG%3E%20capabilities%20to%20deploy%20resources%20in%20parallel%20which%20makes%20it%20faster%20than%20serial%20deployments%2C%20and%20also%20the%20feature%20to%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Etrack%20deployments%3C%2FSTRONG%3E%20via%20the%20Azure%20portal.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_0-1585348001783.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180055iE57249D9DD66A415%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_0-1585348001783.png%22%20alt%3D%22Cyb3rWard0g_0-1585348001783.png%22%20%2F%3E%3C%2FSPAN%3E%3CFIGCAPTION%20class%3D%22imageCaption%22%3E%3C%2FFIGCAPTION%3E%3CA%20class%3D%22markup--anchor%20markup--figure-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23why-choose-resource-manager-templates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23why-choose-resource-manager-templates%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23why-choose-resource-manager-templates%3C%2FA%3E%3C%2FFIGURE%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--1808624454%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%20id%3D%22toc-hId--1808624458%22%3EAdditional%20Reading%3C%2FH4%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23why-choose-resource-manager-templates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23why-choose-resource-manager-templates%22%3EWhy%20choose%20Resource%20Manager%20templates%3F%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Ftemplate-syntax%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Ftemplate-syntax%22%3EARM%20templates%20structure%20and%20syntax%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23template-deployment-process%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%23template-deployment-process%22%3EARM%20templates%20to%20REST%20API%20operations%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--22176199%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%20id%3D%22toc-hId--22176203%22%3EOn-boarding%20Sentinel%20with%20ARM%20Templates%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ENow%20that%20we%20know%20a%20little%20bit%20more%20about%20Azure%20Resource%20Manager%20services%2C%20we%20are%20ready%20to%20deploy%20Azure%20Sentinel.%20One%20document%20that%20I%20recommend%20to%20get%20familiar%20with%20to%20learn%20more%20about%20Azure%20resources%20mapped%20to%20ARM%20template%20resource%20types%20is%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2F%22%3Ethis%20one%3C%2FA%3E.%20In%20this%20section%2C%20we%20are%20going%20to%20deploy%20a%20Log%20Analytics%20workspace%20and%20enable%20Azure%20Sentinel.%20Remember%20that%20I%20provide%20the%20template%20for%20you%20so%20that%20you%20can%20follow%20along.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-668385275%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%20id%3D%22toc-hId-668385271%22%3E1.%20Deploying%20a%20Log%20Analytics%20Workspace%20ARM%26nbsp%3BTemplate%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EA%20Log%20Analytics%20workspace%20can%20be%20found%20under%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationalinsights%2Fallversions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationalinsights%2Fallversions%22%3EMicrosoft.OperationalInsights%3C%2FA%3E%20resource%20types%20as%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationalinsights%2F2015-11-01-preview%2Fworkspaces%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationalinsights%2F2015-11-01-preview%2Fworkspaces%22%3EMicrosoft.OperationalInsights%2Fworkspaces%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3E%3CCODE%20class%3D%22markup--code%20markup--pre-code%22%3E%7B%3CBR%20%2F%3E%20%20%22name%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%22type%22%3A%20%22Microsoft.OperationalInsights%2Fworkspaces%22%2C%3CBR%20%2F%3E%20%20%22apiVersion%22%3A%20%222015-11-01-preview%22%2C%3CBR%20%2F%3E%20%20%22location%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%22tags%22%3A%20%7B%7D%2C%3CBR%20%2F%3E%20%20%22properties%22%3A%20%7B%3CBR%20%2F%3E%20%20%20%20%22sku%22%3A%20%7B%3CBR%20%2F%3E%20%20%20%20%20%20%22name%22%3A%20%22string%22%3CBR%20%2F%3E%20%20%20%20%7D%2C%3CBR%20%2F%3E%20%20%20%20%22retentionInDays%22%3A%20%22integer%22%3CBR%20%2F%3E%20%20%7D%2C%3CBR%20%2F%3E%20%20%22resources%22%3A%20%5B%5D%3CBR%20%2F%3E%7D%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EI%20created%20an%20initial%20template%20with%20some%20parameters%20to%20make%20it%20modular%20for%20anyone%20to%20use.%20This%20is%20the%20initial%20template%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20class%3D%22graf%20graf--p%22%3ETemplate%20Link%3A%20%3CA%20href%3D%22https%3A%2F%2Fgist.github.com%2FCyb3rWard0g%2F27b32e085607fb84816d24831f03a17e%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgist.github.com%2FCyb3rWard0g%2F27b32e085607fb84816d24831f03a17e%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--1139069188%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%20id%3D%22toc-hId--1139069192%22%3E2.%20Enabling%20Azure%20Sentinel%20ARM%26nbsp%3BTemplate%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ENext%2C%20I%20needed%20to%20define%20the%20Azure%20Sentinel%20solution%20and%20enable%20it%20on%20the%20top%20of%20the%20Log%20Analytics%20workspace.%20You%20can%20do%20it%20with%20a%20resource%20type%20found%20under%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationsmanagement%2Fallversions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationsmanagement%2Fallversions%22%3EMicrosoft.OperationsManagement%3C%2FA%3E%20resource%20types%20as%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationsmanagement%2F2015-11-01-preview%2Fsolutions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%2Fmicrosoft.operationsmanagement%2F2015-11-01-preview%2Fsolutions%22%3EMicrosoft.OperationsManagement%2Fsolutions%3C%2FA%3E%26nbsp%3B.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3E%3CCODE%20class%3D%22markup--code%20markup--pre-code%22%3E%7B%3CBR%20%2F%3E%20%20%22name%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%22type%22%3A%20%22Microsoft.OperationsManagement%2Fsolutions%22%2C%3CBR%20%2F%3E%20%20%22apiVersion%22%3A%20%222015-11-01-preview%22%2C%3CBR%20%2F%3E%20%20%22location%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%22tags%22%3A%20%7B%7D%2C%3CBR%20%2F%3E%20%20%22plan%22%3A%20%7B%3CBR%20%2F%3E%20%20%20%20%22name%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%20%20%22publisher%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%20%20%22promotionCode%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%20%20%22product%22%3A%20%22string%22%3CBR%20%2F%3E%20%20%7D%2C%3CBR%20%2F%3E%20%20%22properties%22%3A%20%7B%3CBR%20%2F%3E%20%20%20%20%22workspaceResourceId%22%3A%20%22string%22%2C%3CBR%20%2F%3E%20%20%20%20%22containedResources%22%3A%20%5B%3CBR%20%2F%3E%20%20%20%20%20%20%22string%22%3CBR%20%2F%3E%20%20%20%20%5D%2C%3CBR%20%2F%3E%20%20%20%20%22referencedResources%22%3A%20%5B%3CBR%20%2F%3E%20%20%20%20%20%20%22string%22%3CBR%20%2F%3E%20%20%20%20%5D%3CBR%20%2F%3E%20%20%7D%3CBR%20%2F%3E%7D%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EI%20added%20that%20to%20our%20initial%20ARM%20template%20and%20this%20is%20the%20final%20result%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20class%3D%22graf%20graf--p%22%3ETemplate%20Link%3A%20%3CA%20href%3D%22https%3A%2F%2Fgist.github.com%2FCyb3rWard0g%2F8d5691f90ee7bda0502b5db005be5503%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgist.github.com%2FCyb3rWard0g%2F8d5691f90ee7bda0502b5db005be5503%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThat%E2%80%99s%20it!%20You%20can%20download%20it%20and%20use%20it%20for%20the%20next%20steps.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--1149572292%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%20id%3D%22toc-hId--1149572296%22%3EExecuting%20ARM%20Templates%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThere%20are%20a%20few%20ways%20to%20execute%20ARM%20templates%2C%20and%20it%20all%20depends%20on%20how%20comfortable%20you%20are%20with%20the%20Azure%20portal%20and%20Azure%20tool-kits%20(e.g.%20Azure%20CLI)%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-2039005119%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%20id%3D%22toc-hId-2039005115%22%3EPrerequisites%3C%2FH4%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EAn%20active%20Azure%20Subscription%3A%3C%2FSTRONG%3E%20If%20you%20don%E2%80%99t%20have%20one%2C%20create%20a%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Ffree%2F%3FWT.mc_id%3DA261C142F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fazure.microsoft.com%2Ffree%2F%3FWT.mc_id%3DA261C142F%22%3Efree%20account%3C%2FA%3E.%20You%20might%20be%20eligible%20for%20some%20free%20credits%20for%20the%20first%2030%20days.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Fmanage-resource-groups-portal%23what-is-a-resource-group%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Fmanage-resource-groups-portal%23what-is-a-resource-group%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EA%20Resource%20Group%3C%2FSTRONG%3E%3C%2FA%3E%3A%20A%20container%20that%20holds%20related%20resources%20for%20an%20Azure%20solution.%20You%20can%20use%20an%20existing%20one%2C%20but%20if%20this%20is%20your%20first%20time%20playing%20with%20Azure%20resources%2C%20you%20can%20create%20one%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Fmanage-resource-groups-portal%23create-resource-groups%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Fmanage-resource-groups-portal%23create-resource-groups%22%3Efollowing%20these%20instructions%3C%2FA%3E.%20You%20can%20also%20do%20it%20while%20deploying%20and%20ARM%20template%20via%20the%20Azure%20portal.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-2028502015%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%20id%3D%22toc-hId-2028502011%22%3EOption%201%3A%20Using%20Azure%26nbsp%3BCLI%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EIf%20you%20want%20to%20use%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3E%20one%20command%3C%2FSTRONG%3E%20to%20deploy%20an%20ARM%20template%2C%20then%20this%20option%20is%20for%20you.%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcli%2Fazure%2F%3Fview%3Dazure-cli-latest%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcli%2Fazure%2F%3Fview%3Dazure-cli-latest%22%3EThe%20Azure%20command-line%20interface%20(CLI)%3C%2FA%3E%20is%20Microsoft%E2%80%99s%20cross-platform%20command-line%20experience%20for%20managing%20Azure%20resources.%20It%20can%20be%20installed%20in%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcli%2Fazure%2Finstall-azure-cli%3Fview%3Dazure-cli-latest%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcli%2Fazure%2Finstall-azure-cli%3Fview%3Dazure-cli-latest%22%3EWindows%2C%20macOS%20and%20Linux%3C%2FA%3E%20environments.%20In%20addition%2C%20there%20is%20a%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fazure%2Fget-started-azureps%3Fview%3Dazps-3.6.1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Fazure%2Fget-started-azureps%3Fview%3Dazps-3.6.1%22%3EPowerShell%20version%3C%2FA%3E%20of%20it%20and%20also%20an%20interactive%2C%20authenticated%2C%20browser-accessible%20option%20known%20as%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-shell%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-shell%2Foverview%22%3EAzure%20Cloud%20Shell%3C%2FA%3E.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EWe%20can%20start%20using%20Azure%20CLI%20and%20create%20a%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Fmanage-resource-groups-portal%23what-is-a-resource-group%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Fmanage-resource-groups-portal%23what-is-a-resource-group%22%3EResource%20Group%3C%2FA%3E%20if%20you%20have%20not%20done%20it%20yet.%20Run%20the%20following%20command%20to%20create%20one%20in%20a%20specific%20location%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Eaz%20group%20create%20--location%20eastus%20--resource-group%20SentinelDemo%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ENext%2C%20you%20can%20run%20the%20following%20command%20to%20execute%20the%20ARM%20template%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Eaz%20group%20deployment%20create%20--name%20SentinelDeploy%20--resource-group%20SentinelDemo%20--template-file%20%3CARM%20template%3D%22%22%20name%3D%22%22%3E.json%20--parameters%20workspaceName%3DSentinelDemo%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E%3C%2FCODE%3E%3C%2FARM%3E%3C%2FPRE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3Eaz%20group%20deployment%20create%3C%2FCODE%3E%3A%20Start%20a%20deployment%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E--name%3C%2FCODE%3E%26nbsp%3B%3A%20Name%20of%20your%20deployment%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E--resource-group%3C%2FCODE%3E%3A%20Name%20of%20the%20Azure%20Resource%20group%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E--template-file%3C%2FCODE%3E%26nbsp%3B%3A%20Template%20that%20I%20put%20together%20for%20this%20deployment.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E--parameters%3C%2FCODE%3E%26nbsp%3B%3A%20Deployment%20parameter%20values%20(key%3Dvalue).%20Provide%20a%20name%20for%20your%20Log%20Analytics%20workspace.%20%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EThe%20name%20must%20be%20globally%20unique%20across%20all%20Azure%20subscriptions%3C%2FSTRONG%3E.%20I%20take%20care%20of%20that%20for%20you%20in%20the%20template%20by%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fgist.github.com%2FCyb3rWard0g%2F8d5691f90ee7bda0502b5db005be5503%23file-ala-workspace-sentinel-json-L58%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgist.github.com%2FCyb3rWard0g%2F8d5691f90ee7bda0502b5db005be5503%23file-ala-workspace-sentinel-json-L58%22%3Eadding%20a%20unique%20string%20after%3C%2FA%3E%20the%20name%20you%20provide.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ETrack%20your%20deployment%3A%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%3EAzure%20Portal%3C%2FA%3E%26gt%3BResource%20Group%20Name%26gt%3BDeployments%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_0-1585348193219.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180056iA477A159FCD1F019%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_0-1585348193219.png%22%20alt%3D%22Cyb3rWard0g_0-1585348193219.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_1-1585348205234.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180057i19BC897E17E6E101%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_1-1585348205234.png%22%20alt%3D%22Cyb3rWard0g_1-1585348205234.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThat%E2%80%99s%20it!%20once%20your%20deployment%20completes%2C%20you%20will%20be%20able%20to%20access%20the%20main%20Azure%20Sentinel%20interface.%20Before%20we%20do%20that%2C%20let%20me%20show%20you%20another%20way%20to%20execute%20our%20ARM%20template.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--474115927%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%20id%3D%22toc-hId--474115931%22%3EOption%202%3A%20Using%20Azure%26nbsp%3BPortal%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CBR%20%2F%3EIt%20takes%20a%20few%20more%20clicks%20to%20do%20it%20via%20the%20Azure%20portal%2C%20but%20it%20is%20easy%20to%20follow%3A%3C%2FP%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EGo%20to%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%3Ehttps%3A%2F%2Fportal.azure.com%2F%3C%2FA%3E%20and%20click%20on%20the%20%22Create%20a%20resource%E2%80%9D%20option%20on%20the%20top%20left%20of%20your%20screen%20to%20create%20resources.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_2-1585348217563.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180058iCFD14252692D34EF%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_2-1585348217563.png%22%20alt%3D%22Cyb3rWard0g_2-1585348217563.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3ELook%20for%20%E2%80%9CTemplate%20Deployment%E2%80%9D%20and%20click%20on%20%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3ECreate%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_3-1585348252989.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180059iC47752AA11AF6DD5%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_3-1585348252989.png%22%20alt%3D%22Cyb3rWard0g_3-1585348252989.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EChoose%3A%20%E2%80%9C%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EBuild%20your%20own%20template%20in%20the%20editor%3C%2FSTRONG%3E%E2%80%9D%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_4-1585348271470.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180060i5ED2E1305E9E7FE3%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_4-1585348271470.png%22%20alt%3D%22Cyb3rWard0g_4-1585348271470.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EUpload%20the%20template%20we%20put%20together.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_5-1585348285545.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180061i37F75700D287AD1D%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_5-1585348285545.png%22%20alt%3D%22Cyb3rWard0g_5-1585348285545.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EOnce%20the%20template%20is%20uploaded%2C%20you%20will%20see%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3Eparameters%3C%2FSTRONG%3E%20and%20%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3Eresources%3C%2FSTRONG%3E%20sections%20get%20populated.%20Click%20save.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_6-1585348303563.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180062i72075BC60073AAE0%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_6-1585348303563.png%22%20alt%3D%22Cyb3rWard0g_6-1585348303563.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3ENext%2C%20you%20need%20to%20set%20your%20subscription%20and%20resource%20group%20names.%20As%20you%20can%20see%20in%20the%20image%20below%2C%20you%20can%20directly%20create%20an%20Azure%20Resource%20Group%20if%20you%20don%E2%80%99t%20have%20one%20yet.%20Also%2C%20don%E2%80%99t%20forget%20to%20agree%20to%20the%20terms%20and%20conditions.%20Click%20purchase.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_7-1585348319658.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180063iDF515E1EA0852285%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_7-1585348319658.png%22%20alt%3D%22Cyb3rWard0g_7-1585348319658.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EThen%2C%20you%20can%20track%20the%20deployment%20of%20your%20Azure%20Sentinel%20resources%20by%20going%20to%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%3EAzure%20Portal%3C%2FA%3E%20%26gt%3B%20Resource%20Group%20Name%20%26gt%3B%20Deployments%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_8-1585348332327.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180064i42C4FB6454E0DDF0%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_8-1585348332327.png%22%20alt%3D%22Cyb3rWard0g_8-1585348332327.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThat%E2%80%99s%20it!%20once%20your%20deployment%20completes%2C%20you%20will%20be%20able%20to%20access%20the%20main%20Azure%20Sentinel%20interface.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--p%22%20id%3D%22toc-hId-1884314187%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%20id%3D%22toc-hId-1884314183%22%3EAccessing%20Azure%26nbsp%3BSentinel%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20class%3D%22graf%20graf--p%22%3ESearch%20for%20%E2%80%9C%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel%3C%2FSTRONG%3E%E2%80%9D%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_9-1585348352135.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180065iBA3B5C181DA3A2DA%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_9-1585348352135.png%22%20alt%3D%22Cyb3rWard0g_9-1585348352135.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CUL%3E%0A%3CLI%20class%3D%22graf%20graf--p%22%3ESelect%20the%20Azure%20Sentinel%20workspace%20that%20you%20just%20created.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_10-1585348365030.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180066iE64AC88A6B1993ED%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_10-1585348365030.png%22%20alt%3D%22Cyb3rWard0g_10-1585348365030.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EYou%20will%20be%20taken%20to%20the%20main%20Azure%20Sentinel%20interface.%20That%20was%20easy%20right%3F%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_11-1585348375170.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180067i39C5086E894E719A%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_11-1585348375170.png%22%20alt%3D%22Cyb3rWard0g_11-1585348375170.png%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FFIGURE%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId-76859724%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%20id%3D%22toc-hId-76859720%22%3EWait%2C%20what%3F%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%20graf--startsWithDoubleQuote%22%3E%3CEM%20class%3D%22markup--em%20markup--p-em%22%3E%3CBR%20%2F%3E%E2%80%9C%3C%2FEM%3EWhy%20do%20I%20have%20to%20do%20all%20that%20with%20ARM%20templates%20when%20I%20can%20just%20follow%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard%23enable-azure-sentinel-%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard%23enable-azure-sentinel-%22%3Ethese%20instructions%3C%2FA%3E%20and%20with%20a%20few%20clicks%20I%20can%20deploy%20one%20too%3F%3CEM%20class%3D%22markup--em%20markup--p-em%22%3E%E2%80%9D%3C%2FEM%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%20graf--startsWithDoubleQuote%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EDeploying%20the%20solution%20while%20working%20in%20a%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3E%20lab%20environment%3C%2FSTRONG%3E%20is%20not%20enough.%20You%20need%20to%20have%20other%20resources%20and%20data%20to%20start%20exploring%20and%20learning%20about%20all%20the%20capabilities%20Azure%20Sentinel%20provides.%20That%20will%20take%20more%20than%20just%20a%20few%20clicks.%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EWhat%20if%20we%20can%20take%20the%20ARM%20template%20that%20we%20just%20used%20and%20run%20other%20nested%20templates%20in%20parallel%20to%20deploy%20other%20resources%20and%20even%20ingest%20pre-recorded%20data%20for%20additional%20research%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--1730594739%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%20id%3D%22toc-hId--1730594743%22%3EEnter%20Sentinel%20To-Go%26nbsp%3B!%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%3C%2FA%3E%20is%20an%20open%20source%20project%20developed%20to%20expedite%20the%20deployment%20of%20an%20Azure%20Sentinel%20lab%20along%20with%20other%20Azure%20resources%20and%20a%20data%20ingestion%20pipeline%20to%20consume%20pre-recorded%20datasets%20for%20research%20purposes.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%20%3C%2FA%3Eis%20part%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%22%3EBlacksmith%20project%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CBLOCKQUOTE%20class%3D%22graf%20graf--blockquote%22%3EThe%20Blacksmith%20project%20focuses%20on%20providing%20dynamic%20easy-to-use%20templates%20for%20security%20researches%20to%20model%20and%20provision%20resources%20to%20automatically%20deploy%20applications%20and%20small%20networks%20in%20the%20cloud.%3C%2FBLOCKQUOTE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%20is%20a%20work%20in%20progress%2C%20and%20I%20welcome%20feedback%20on%20what%20it%20is%20that%20you%20would%20like%20to%20see%20being%20deployed%20along%20with%20an%20Azure%20Sentinel%20solution%20and%20datasets%20you%20would%20like%20to%20work%20with%20in%20your%20lab%20environment.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId-756918094%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%20id%3D%22toc-hId-756918090%22%3EAzure%20Sentinel%20%2B%20Prerecorded%20Datasets%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOne%20of%20the%20features%20that%20I%20have%20noticed%20security%20analysts%20get%20interested%20the%20most%20while%20using%20Azure%20Sentinel%20for%20the%20first%20time%20is%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Flog-query-overview%23what-is-log-analytics%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Flog-query-overview%23what-is-log-analytics%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ELog%20Analytics%3C%2FSTRONG%3E%3C%2FA%3E%20capabilities.%20Log%20Analytics%20is%20the%20primary%20tool%20in%20the%20Azure%20portal%20for%20writing%20log%20queries%20written%20in%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EKusto%20Query%20Language%20(KQL)%3C%2FSTRONG%3E%3C%2FA%3E%20to%20quickly%20retrieve%2C%20consolidate%2C%20and%20analyze%20security%20events.%20Therefore%2C%20I%20decided%20to%20find%20a%20way%20for%20researchers%20to%20learn%20about%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%3EKQL%3C%2FA%3E%20with%20pre-recorded%20datasets.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EFortunately%2C%20the%20Log%20Analytics%20workspace%20allows%20the%20collection%20of%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-custom-logs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-custom-logs%22%3Ecustom%20logs%3C%2FA%3E%20via%20its%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EHTTP%20Data%20Collector%20API%3C%2FSTRONG%3E%3C%2FA%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3E.%3C%2FSTRONG%3E%20If%20you%20want%20to%20learn%20how%20to%20do%20it%20with%20code%2C%20there%20are%20some%20basic%20examples%20in%20Azure%20docs%20for%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23powershell-sample%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23powershell-sample%22%3EPowershell%3C%2FA%3E%2C%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23c-sample%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23c-sample%22%3EC%23%3C%2FA%3E%20and%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23python-2-sample%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23python-2-sample%22%3EPython%3C%2FA%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3E.%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--1050536369%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%20id%3D%22toc-hId--1050536373%22%3EData%20Ingestion%20Pipeline%26nbsp%3BDesign%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CBR%20%2F%3EIn%20this%20section%20I%20will%20share%20a%20few%20of%20my%20favorite%20ways%20to%20send%20pre-recorded%20datasets%20to%20a%20Log%20Analytics%20workspace%20custom%20log%20table.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH3%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId-1566059183%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%20id%3D%22toc-hId-1566059179%22%3EPython%20Script%20-%26gt%3B%20Log%20Analytics%20Workspace%3C%2FH3%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_12-1585348389443.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180068i2FD09C8353C628A2%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_12-1585348389443.png%22%20alt%3D%22Cyb3rWard0g_12-1585348389443.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThis%20is%20one%20of%20the%20simplest%20ways%20to%20send%20data%20directly%20to%20a%20log%20analytics%20workspace.%20I%20took%20the%20basic%20example%20available%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23python-2-sample%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23python-2-sample%22%3Ehere%2C%3C%2FA%3E%20and%20extended%20it%20a%20little%20bit%20to%20be%20able%20to%20read%20from%20a%20JSON%20file%20or%20a%20folder%2C%20show%20a%20progress%20bar%2C%20and%20send%20smaller%20sized%20chunks%20of%205MB%20per%20POST%20request.%20Make%20sure%20you%20read%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23data-limits%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-collector-api%23data-limits%22%3EData%20Limits%3C%2FA%3E%20while%20using%20a%20similar%20approach.%20I%20also%20extended%20the%20PowerShell%20script%20available%20and%20created%20a%20proof%20of%20concept%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%2Fblob%2Fmaster%2Fala-powershell-data-producer.ps1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%2Fblob%2Fmaster%2Fala-powershell-data-producer.ps1%22%3Ehere%3C%2FA%3E.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThe%20script%20is%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%2Fblob%2Fmaster%2Fala-python-data-producer.py%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eavailable%20here%3C%2FA%3E%20and%20all%20the%20information%20you%20will%20need%20from%20the%20log%20analytics%20workspace%20can%20be%20found%20in%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%3EAzure%20Portal%3C%2FA%3E%26gt%3BLog%20Analytics%20Workspace%26gt%3BAdvanced%20Settings.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_13-1585348408886.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180069i4FDC0E4A00149C89%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_13-1585348408886.png%22%20alt%3D%22Cyb3rWard0g_13-1585348408886.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ENext%2C%20we%20need%20a%20data%20sample%20for%20this%20exercise.%20Therefore%2C%20the%20project%20comes%20with%20a%20few%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%2Fsamples%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%2Fsamples%22%3Edata%20samples%20in%20this%20folder%3C%2FA%3E.%20Download%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Fblob%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%2Fsamples%2Fdataset-sample-small.tar.gz%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Fblob%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%2Fsamples%2Fdataset-sample-small.tar.gz%22%3Edataset-sample-small.tar.gz%3C%2FA%3E%20to%20your%20local%20computer%20and%20decompress%20it.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Etar%20-xzvf%20dataset-sample-small.tar.gz%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ENext%2C%20send%20it%20over%20by%20running%20these%20commands%20in%20your%20local%20computer%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Epython3%20ala-python-data-producer.py%20-w%20%26lt%3BWorkspaceID%26gt%3B%20-k%20%26lt%3BSharedKey%26gt%3B%20-l%20%22onesample%22%20-f%20dataset-sample-small.json%20-v%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOnce%20it%20completes%20go%20to%20your%20Azure%20Sentinel%20interface%20and%20click%20on%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ELogs%3C%2FSTRONG%3E.%20You%20can%20see%20that%20there%20are%20no%20events%20yet.%20It%20usually%20takes%20from%205%E2%80%9310%20mins.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_14-1585348428647.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180070iD04BF952F998315B%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_14-1585348428647.png%22%20alt%3D%22Cyb3rWard0g_14-1585348428647.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EYou%20can%20see%20a%20new%20table%20under%20customs%20logs%20with%20the%20event%20schemas.%20Remember%20that%20not%20every%20event%20will%20have%20the%20same%20schema.%20Make%20sure%20you%20understand%20the%20schema%20of%20your%20events%20before%20running%20queries.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_15-1585348441445.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180071i9642CF5653F2BEA5%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_15-1585348441445.png%22%20alt%3D%22Cyb3rWard0g_15-1585348441445.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EBased%20on%20the%20event%20schemas%2C%20we%20can%20run%20the%20following%20query%20to%20see%20what%20events%20we%20are%20working%20with%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Eonesample_CL%3CBR%20%2F%3E%7C%20summarize%20count()%20by%20winlog_channel_s%2C%20winlog_event_id_d%2C%20winlog_task_s%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_16-1585348455615.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180072i087D28DCF86B5210%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_16-1585348455615.png%22%20alt%3D%22Cyb3rWard0g_16-1585348455615.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThat%E2%80%99s%20it!%20This%20is%20a%20very%20practical%20way%20to%20ingest%20custom%20logs%2C%20but%20might%20not%20scale%20with%20larger%20files%20or%20hundreds%20of%20files%20in%20a%20loop.%20Therefore%2C%20I%20wanted%20to%20also%20provide%20another%20option%20that%20would%20allow%20me%20to%20send%20events%20to%20a%20more%20robust%20pipeline%20and%20let%20it%20handle%20the%20whole%20process.%20This%20is%20a%20proof%20of%20concept%20and%20works%20very%20well%20in%20a%20lab%20environment.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH3%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--241395280%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%20id%3D%22toc-hId--241395284%22%3EAzure%20Event%20Hubs%20-%26gt%3B%20Logstash%20-%26gt%3B%20Log%20Analytics%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CBR%20%2F%3EI%20like%20to%20use%20existing%20tools%20that%20are%20proven%20to%20work%20at%20scale%20and%20this%20is%20not%20the%20exception.%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ETL%3BDR%3C%2FSTRONG%3E%E2%80%8A%E2%80%94%E2%80%8AI%20use%20Kafkacat%20to%20read%20json%20files%20stored%20locally%20and%20send%20them%20over%20to%20an%20Azure%20Event%20Hub.%20Next%2C%20Logstash%20reads%20them%20from%20Azure%20Event%20Hub%2C%20and%20sends%20them%20over%20to%20a%20Log%20Analytics%20workspace.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_0-1585348612569.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180073iDB6F085A5013BCF0%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_0-1585348612569.png%22%20alt%3D%22Cyb3rWard0g_0-1585348612569.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EIn%20more%20details%20the%20following%20is%20happening%20in%20the%20image%20above%3A%3C%2FP%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EFirst%2C%20I%20use%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fedenhill%2Fkafkacat%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fedenhill%2Fkafkacat%22%3EKafkacat%3C%2FA%3E%20in%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.confluent.io%2Fcurrent%2Fapp-development%2Fkafkacat-usage.html%23producer-mode%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.confluent.io%2Fcurrent%2Fapp-development%2Fkafkacat-usage.html%23producer-mode%22%3EProducer%20mode%3C%2FA%3E%20to%20read%20contents%20of%20a%20JSON%20file%20and%20send%20them%20over%20to%20a%20Kafka%20server.%20Kafkacat%20is%20a%20generic%20non-JVM%20producer%20and%20consumer%20for%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fkafka.apache.org%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fkafka.apache.org%2F%22%3EApache%20Kafka%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EInstead%20of%20a%20Kafka%20server%2C%20I%20use%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fevent-hubs%2Fevent-hubs-about%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fevent-hubs%2Fevent-hubs-about%22%3EAzure%20Event%20Hubs%3C%2FA%3E%20with%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fevent-hubs%2Fevent-hubs-for-kafka-ecosystem-overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fevent-hubs%2Fevent-hubs-for-kafka-ecosystem-overview%22%3EKafka%20features%20enabled%3C%2FA%3E%20to%20receive%20and%20store%20events%20from%20Kafkacat.%20Azure%20Event%20Hubs%20is%20a%20server-less%20big%20data%20streaming%20platform%20and%20event%20ingestion%20service.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3ENext%2C%20I%20use%20a%20Linux%20VM%20with%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Findex.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Findex.html%22%3ELogstash%3C%2FA%3E%20installed%20as%20a%20docker%20container%20to%20read%20events%20from%20the%20Azure%20Event%20Hub.%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Findex.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Findex.html%22%3ELogstash%3C%2FA%3E%20is%20an%20open%20source%20data%20collection%20engine%20with%20real-time%20pipelining%20capabilities.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3EFinally%2C%20I%20use%20the%20same%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Findex.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Findex.html%22%3ELogstash%3C%2FA%3E%20server%20to%20send%20events%20collected%20from%20the%20Azure%20Event%20Hub%20to%20the%20Azure%20Sentinel%E2%80%99s%20workspace%20for%20further%20analysis.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EI%20already%20provide%20the%20following%20configurations%20as%20part%20of%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%20%3C%2FSTRONG%3Eproject%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3E.%3C%2FSTRONG%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CH4%20class%3D%22graf%20graf--p%22%20id%3D%22toc-hId--1919767024%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%20id%3D%22toc-hId--1919767028%22%3EEvent%20Hub%20-%26gt%3B%20Logstash%26nbsp%3BConf%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FH4%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThis%20is%20the%20Logstash%20input%20config%20file%20to%20consume%20events%20from%20an%20Azure%20Event%20Hub.%20The%20plugin%20used%20is%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-azure_event_hubs.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-azure_event_hubs.html%22%3ELogstash%20Azure%20Event%20Hubs%20input%20plugin%3C%2FA%3E.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Einput%20%7B%3CBR%20%2F%3E%20%20azure_event_hubs%20%7B%3CBR%20%2F%3E%20%20%20%20event_hub_connections%20%3D%26gt%3B%20%5B%22%24%7BEVENTHUB_CONNECTIONSTRING%7D%22%5D%3CBR%20%2F%3E%20%20%20%20threads%20%3D%26gt%3B%202%3CBR%20%2F%3E%20%20%20%20initial_position%20%3D%26gt%3B%20%22end%22%3CBR%20%2F%3E%20%20%20%20%23codec%20%3D%26gt%3B%20%22json%22%3CBR%20%2F%3E%20%20%7D%3CBR%20%2F%3E%7D%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EI%20do%20not%20use%20the%20input%20%3CCODE%20class%3D%22markup--code%20markup--p-code%22%3Ecodec%20%3D%26gt%3B%20%22json%22%3C%2FCODE%3E%20property%20because%20I%20do%20not%20want%20to%20unpack%20the%20event%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EMessage%3C%2FSTRONG%3E%20field%20and%20exceed%20the%20max%20number%20(500)%20of%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Ecustom%20fields%3C%2FSTRONG%3E%20per%20data%20type%20in%20the%20Log%20Analytics%20workspace.%3C%2FP%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-567745809%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%20id%3D%22toc-hId-567745805%22%3E%26nbsp%3B%3C%2FH4%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--541546713%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%20id%3D%22toc-hId--541546717%22%3ELogstash%20Conf%20-%26gt%3B%20Log%20Analytics%20Workspace%3C%2FH4%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThis%20is%20the%20Logstash%20output%20config%20file%20to%20send%20the%20events%20that%20it%20collects%20from%20the%20Azure%20Event%20Hub%20to%20a%20Log%20Analytics%20workspace.%20The%20plugin%20used%20is%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fyokawasa%2Flogstash-output-azure_loganalytics%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fyokawasa%2Flogstash-output-azure_loganalytics%22%3ELog%20Analytics%20output%20Logstash%20plugin%3C%2FA%3E%20developed%20by%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fyokawasa%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fyokawasa%22%3EYokawasa%3C%2FA%3E.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Eoutput%20%7B%3CBR%20%2F%3E%20%20azure_loganalytics%20%7B%3CBR%20%2F%3E%20%20%20%20customer_id%20%3D%26gt%3B%20%22%24%7BWORKSPACE_ID%7D%22%3CBR%20%2F%3E%20%20%20%20shared_key%20%3D%26gt%3B%20%22%24%7BWORKSPACE_KEY%7D%22%3CBR%20%2F%3E%20%20%20%20log_type%20%3D%26gt%3B%20%22prerecorded%22%3CBR%20%2F%3E%20%20%20%20%3CCODE%20class%3D%22markup--code%20markup--pre-code%22%3Eflush_items%20%3D%26gt%3B%2010%3CBR%20%2F%3E%20%20%20%20flush_interval_time%20%3D%26gt%3B%205%3CBR%20%2F%3E%20%20%3C%2FCODE%3E%7D%3CBR%20%2F%3E%23stdout%20%7B%20codec%20%3D%26gt%3B%20rubydebug%20%7D%3CBR%20%2F%3E%7D%3C%2FPRE%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-1945966120%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%20id%3D%22toc-hId-1945966116%22%3E%26nbsp%3B%3C%2FH4%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-138511657%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%20id%3D%22toc-hId-138511653%22%3EARM%20Template%20Deployment%3C%2FH4%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOne%20thing%20I%20added%20to%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%20repository%20is%20a%20%E2%80%9C%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EDeploy%20to%20Azure%E2%80%9D%3C%2FSTRONG%3E%20badge%20used%20on%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2Fazure-quickstart-templates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2Fazure-quickstart-templates%22%3EAzure%20quick-start%20templates%3C%2FA%3E%20to%20upload%20the%20ARM%20template%20directly%20to%20the%20Azure%20portal.%20Very%20convenient!%20Click%20on%20the%20badge!%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_1-1585348635003.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180074i132BCB77CC655B49%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_1-1585348635003.png%22%20alt%3D%22Cyb3rWard0g_1-1585348635003.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EYou%20will%20be%20taken%20to%20the%20interface%20to%20set%20deployment%20parameters.%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EOne%20thing%20to%20pay%20attention%20to%3C%2FSTRONG%3E%20is%20the%20virtual%20machine%20size.%20If%20you%20are%20in%20%3CCODE%20class%3D%22markup--code%20markup--p-code%22%3Ewestus%3C%2FCODE%3E%2C%20you%20need%20to%20switch%20it%20to%20%3CCODE%20class%3D%22markup--code%20markup--p-code%22%3EStandard_A3%3C%2FCODE%3E%26nbsp%3B.%20Let%20me%20know%20if%20I%20need%20to%20add%20more%20options.%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EDon%E2%80%99t%20forget%20to%20agree%20to%20the%20terms%20and%20conditions%20at%20the%20bottom%20of%20the%20page%3C%2FSTRONG%3E!.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_2-1585348652024.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180075i6951ABECA49C968C%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_2-1585348652024.png%22%20alt%3D%22Cyb3rWard0g_2-1585348652024.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EMonitor%20your%20deployment.%20It%20should%20take%20around%208%E2%80%9310%20minutes.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_3-1585348665121.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180076i4C4879D600BB5C2B%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_3-1585348665121.png%22%20alt%3D%22Cyb3rWard0g_3-1585348665121.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOnce%20it%20completes%2C%20you%20should%20be%20able%20to%20send%20prerecorded%20data%20from%20your%20local%20computer%20to%20the%20Azure%20Event%20Hub.%3C%2FP%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--1668942806%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%20id%3D%22toc-hId--1668942810%22%3E%26nbsp%3B%3C%2FH4%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-818570027%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%20id%3D%22toc-hId-818570023%22%3ESending%20events%20to%20the%20Azure%20Event%26nbsp%3BHub%3C%2FH4%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EFirst%2C%20create%20a%20local%20Kafkacat%20configuration%20file%20to%20define%20a%20few%20properties%20to%20be%20able%20to%20access%20the%20Azure%20Event%20Hub.%20I%20created%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Fblob%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%2Fsamples%2Fkafkacat-Example.conf%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Fblob%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%2Fsamples%2Fkafkacat-Example.conf%22%3Eone%20for%20you%3C%2FA%3E.%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EYou%20will%20need%20to%20get%20the%20following%20values%20and%20paste%20them%20in%20the%20config%20file.%3C%2FP%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EEvent%20Hub%20namespace%3A%20%3C%2FSTRONG%3EGet%20it%20from%20the%20Event%20Hub%20resource.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--li-strong%22%3EEvent%20Hub%20Connection%20String%3C%2FSTRONG%3E%3A%20You%20can%20get%20it%20following%20%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fevent-hubs%2Fevent-hubs-get-connection-string%23get-connection-string-from-the-portal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fevent-hubs%2Fevent-hubs-get-connection-string%23get-connection-string-from-the-portal%22%3Ethese%20steps%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ESecond%2C%20we%20need%20a%20sample%20dataset%20to%20send%20over%20to%20our%20Azure%20Event%20Hub.%20We%20can%20use%20the%20same%20dataset%20we%20used%20earlier%20with%20the%20Python%20script.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ENext%2C%20in%20your%20local%20computer%2C%20run%20Kafkacat%20in%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.confluent.io%2Fcurrent%2Fapp-development%2Fkafkacat-usage.html%23producer-mode%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.confluent.io%2Fcurrent%2Fapp-development%2Fkafkacat-usage.html%23producer-mode%22%3EProducer%20mode%3C%2FA%3E%20as%20shown%20below.%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Ekafkacat%20-b%20%26lt%3BEVENTHUB-NAMESPACE%26gt%3B.servicebus.windows.net%3A9093%20-t%20%26lt%3BEVENTHUB-NAME%26gt%3B%20-F%20%26lt%3BKAFKACAT-FILE%26gt%3B.conf%20-P%20-l%20dataset-sample.json%3C%2FPRE%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E-b%3C%2FCODE%3E%26nbsp%3B%3A%20Bootstrap%20broker(s)%20(host%5B%3Aport%5D).%20Your%20Event%20Hub%20Namespace%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E-t%26nbsp%3B%3C%2FCODE%3E%3A%20Topic%20to%20produce%2Fsend%20events%20to.%20The%20name%20of%20you%20Event%20Hub.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E-F%3C%2FCODE%3E%26nbsp%3B%3A%20Read%20configuration%20properties%20from%20the%20Kafkacat.conf%20file.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E-P%3C%2FCODE%3E%26nbsp%3B%3A%20Producer%20Mode%26nbsp%3B%3A%20Produce%2FSend%20events.%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CCODE%20class%3D%22markup--code%20markup--li-code%22%3E-l%26nbsp%3B%3C%2FCODE%3E%3A%20Send%20messages%20from%20a%20file.%20Pre-recorded%20dataset.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOnce%20you%20run%20that%20command%2C%20you%20can%20check%20the%20events%20flowing%20through%20the%20Azure%20Event%20Hub.%20Go%20to%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fportal.azure.com%2F%22%3EAzure%20Portal%3C%2FA%3E%20%26gt%3B%20Resource%20Group%20Name%20%26gt%3B%20Event%20Hub%20Namespace%20and%20filter%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EShow%20Metrics%20view%3C%2FSTRONG%3E%20to%20show%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EMessages%3C%2FSTRONG%3E%20only%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3E.%20%3C%2FSTRONG%3EIt%20might%20take%20a%20few%20minutes%20for%20the%20view%20to%20update.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_4-1585348736789.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180077iFA51DEEBA3AD332F%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_4-1585348736789.png%22%20alt%3D%22Cyb3rWard0g_4-1585348736789.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThe%20Azure%20Sentinel%20view%20also%20will%20take%20a%20a%20few%20mins%20to%20update.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_5-1585348746315.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180078iF54D0E1F0BD366E3%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_5-1585348746315.png%22%20alt%3D%22Cyb3rWard0g_5-1585348746315.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--988884436%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%20id%3D%22toc-hId--988884440%22%3EExplore%20the%20Custom%26nbsp%3BLogs%3C%2FH4%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EAs%20you%20already%20know%2C%20click%20on%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ELogs%3C%2FSTRONG%3E%20(Log%20Analytics)%20to%20explore%20the%20custom%20logs%20and%20their%20schema.%20One%20thing%20to%20remember%20is%20that%20the%20events%20flowing%20through%20this%20pipeline%20are%20packed%20inside%20of%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EMessage%3C%2FSTRONG%3E%20field.%20As%20I%20mentioned%20before%2C%20this%20is%20to%20avoid%20exceeding%20the%20max%20number%20(500)%20of%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Ecustom%20fields%3C%2FSTRONG%3E%20per%20data%20type%20in%20case%20you%20send%20a%20lot%20of%20events%20with%20different%20schemas.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_6-1585348802479.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180079iCC383B3B628C991D%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_6-1585348802479.png%22%20alt%3D%22Cyb3rWard0g_6-1585348802479.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EYou%20can%20unpack%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EMessage%3C%2FSTRONG%3E%20field%20and%20get%20to%20specific%20nested%20fields%20with%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%3EKusto%20Query%3C%2FA%3E%20function%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2Fparsejsonfunction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2Fparsejsonfunction%22%3Eparse_json()%3C%2FA%3E.%20This%20function%20interprets%20a%20%3CCODE%20class%3D%22markup--code%20markup--p-code%22%3Estring%3C%2FCODE%3E%20as%20a%20JSON%20value%20and%20returns%20the%20value%20as%20%3CCODE%20class%3D%22markup--code%20markup--p-code%22%3Edynamic%3C%2FCODE%3E%26nbsp%3B.%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Eprerecorded_CL%3CBR%20%2F%3E%7C%20extend%20m%3Dparse_json(Message)%3CBR%20%2F%3E%7C%20summarize%20count()%20by%20EventID%3Dtostring(m.winlog.event_id)%2CEventProvider%3Dtostring(m.winlog.channel)%2CTask%3Dtostring(m.winlog.task)%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_7-1585348820210.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180080iAADC1522C1E3137F%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_7-1585348820210.png%22%20alt%3D%22Cyb3rWard0g_7-1585348820210.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3ERemember%20that%20not%20every%20event%20will%20have%20the%20same%20schema.%20Make%20sure%20you%20understand%20the%20schema%20of%20your%20events%20before%20running%20queries.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId-1240462959%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%20id%3D%22toc-hId-1240462955%22%3E(Optional)%20Loading%20Pre-Recorded%20Datasets%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%20also%20comes%20with%20the%20option%20to%20load%20pre-recorded%20datasets%20right%20at%20deployment%20time.%20It%20leverages%20the%20same%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ELogstash%3C%2FSTRONG%3E%20VM%20for%20the%20data%20ingestion.%20You%20do%20not%20have%20to%20send%20anything%20from%20your%20local%20computer.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_8-1585348834176.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180081i33B4470D08F82B4E%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_8-1585348834176.png%22%20alt%3D%22Cyb3rWard0g_8-1585348834176.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--437908785%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%20id%3D%22toc-hId--437908789%22%3EDownloading%20%26amp%3B%20Decompressing%20Mordor%26nbsp%3BDatasets%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EI%20use%20the%20following%20commands%20to%20download%20and%20decompress%20all%20mordor%20datasets.%20The%20commands%20are%20part%20of%20the%20deployment%20and%20are%20run%20inside%20of%20the%20Linux%20VM.%20You%20do%20not%20have%20to%20run%20anything%20in%20your%20local%20computer.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Egit%20clone%20%3CA%20class%3D%22markup--anchor%20markup--pre-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2Fmordor.git%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2Fmordor.git%22%3Ehttps%3A%2F%2Fgithub.com%2Fhunters-forge%2Fmordor.git%3C%2FA%3E%3CBR%20%2F%3Ecd%20mordor%2Fdatasets%2Fsmall%2F%3CBR%20%2F%3Efind%20.%20-type%20f%20-name%20%22*.tar.gz%22%20-print0%20%7C%20xargs%20-0%20-I%7B%7D%20tar%20xf%20%7B%7D%20-C%20%2Fopt%2Fdatasets%2F%3C%2FPRE%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--2116280529%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%20id%3D%22toc-hId--2116280533%22%3E%26nbsp%3B%3C%2FH4%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-242149585%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%20id%3D%22toc-hId-242149581%22%3EJSON%20files%20-%26gt%3B%20Logstash%26nbsp%3BConf%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThis%20is%20the%20additional%20Logstash%20input%20config%20to%20read%20all%20the%20JSON%20files.%20The%20plugin%20used%20is%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-file.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-file.html%22%3ELogstash%20File%20Input%20plugin%3C%2FA%3E.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Einput%20%7B%3CBR%20%2F%3E%20%20file%20%7B%3CBR%20%2F%3E%20%20%20%20path%20%3D%26gt%3B%20%22%2Fusr%2Fshare%2Flogstash%2Fdatasets%2F*.json%22%3CBR%20%2F%3E%20%20%20%20start_position%20%3D%26gt%3B%20%22beginning%22%3CBR%20%2F%3E%20%20%20%20sincedb_path%20%3D%26gt%3B%20%22%2Fdev%2Fnull%22%3CBR%20%2F%3E%20%20%20%20%23codec%20%3D%26gt%3B%20%22json%22%3CBR%20%2F%3E%20%20%7D%3CBR%20%2F%3E%7D%3C%2FPRE%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--738060218%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%20id%3D%22toc-hId--738060222%22%3E%26nbsp%3B%3C%2FH4%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-1620369896%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%20id%3D%22toc-hId-1620369892%22%3EARM%20Template%20Deployment%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EIf%20you%20have%20resources%20running%20from%20the%20earlier%20deployment%2C%20I%20recommend%20to%20delete%20them%20(Lab%20environment).%20Similar%20to%20our%20previous%20deployment%2C%20click%20on%20the%20%E2%80%9C%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EDeploy%20to%20Azure%E2%80%9D%3C%2FSTRONG%3E%20badge%20available%20in%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%3C%2FA%3E%20and%20enable%20the%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3EIngest%20Mordor%3C%2FSTRONG%3E%20(True)%20parameter%20as%20shown%20below.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_9-1585348858674.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180082i338C61C1D776E3D5%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_9-1585348858674.png%22%20alt%3D%22Cyb3rWard0g_9-1585348858674.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EMonitor%20the%20deployment.%20It%20might%20take%20around%208%E2%80%9310%20minutes%20for%20it%20to%20be%20done.%20When%20it%20is%20complete%2C%20go%20to%20your%20Azure%20Sentinel%20interface.%20Give%20it%202%E2%80%933%20mins%20for%20events%20to%20start%20showing.%20You%20will%20start%20getting%20thousands%20of%20events%20(200K%2B)%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_10-1585348887179.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180083i8DE909390625CECD%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_10-1585348887179.png%22%20alt%3D%22Cyb3rWard0g_10-1585348887179.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EWhat%20I%20do%20while%20I%20wait%20for%20all%20the%20events%20(200k%2B)%20to%20be%20ingested%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_11-1585348900875.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180084iEC02A90A032345E3%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_11-1585348900875.png%22%20alt%3D%22Cyb3rWard0g_11-1585348900875.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGCAPTION%20class%3D%22imageCaption%22%3EPlaying%20and%20exercising%20at%20my%20backyard%20with%20my%20dog%20Pedro%20while%20the%20horses%20watch%20and%20datasets%20get%20ingested.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FFIGCAPTION%3E%0ATake%20advantage%20of%20the%20time%20you%20have%20and%20stretch%20a%20little%20bit!%20Take%20a%20break!%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FFIGURE%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3C%2FFIGURE%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--187084567%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%20id%3D%22toc-hId--187084571%22%3EWhat%20can%20we%20do%20with%20the%26nbsp%3Bdata%3F%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EWe%20can%20do%20the%20same%20as%20before%20and%20explore%20a%20few%20events%20to%20understand%20the%20event%20schemas.%20Also%2C%20since%20those%20events%20were%20generated%20as%20part%20of%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fmordordatasets.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fmordordatasets.com%2F%22%3EMordor%20project%3C%2FA%3E%2C%20you%20could%20focus%20on%20datasets%20mapped%20to%20specific%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fattack.mitre.org%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fattack.mitre.org%2F%22%3EATT%26amp%3BCK%3C%2FA%3E%20tactics%20and%20techniques.%20The%20project%20comes%20with%20a%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fmordordatasets.com%2Fnotebooks%2Fsmall%2Fwindows%2Fwindows.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fmordordatasets.com%2Fnotebooks%2Fsmall%2Fwindows%2Fwindows.html%22%3ENavigator%20View%3C%2FA%3E%20for%20the%20specific%20platforms%20that%20it%20supports%20(Currently%20only%20Windows).%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_12-1585348954272.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180085i1C41B1EB01C3913C%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_12-1585348954272.png%22%20alt%3D%22Cyb3rWard0g_12-1585348954272.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CH3%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--1994539030%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%20id%3D%22toc-hId--1994539034%22%3ELet%E2%80%99s%20Look%20for%20Potential%20Lateral%20Movement%20Techniques%3C%2FH3%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EOne%20thing%20that%20I%20like%20to%20look%20for%20when%20looking%20for%20lateral%20movement%20techniques%20is%20processes%20created%20under%20logon%20sessions%20that%20were%20initially%20created%20as%20part%20of%20a%20network%20authentication%20event%20(Logon%20Type%203).%20One%20example%20can%20be%20adversaries%20leveraging%20the%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fwin32%2Fwmisdk%2Fwmi-start-page%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fwin32%2Fwmisdk%2Fwmi-start-page%22%3EWindows%20Management%20Instrumentation%20(WMI)%3C%2FA%3E%20and%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fwin32%2Fcimwin32prov%2Fwin32-process%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fwin32%2Fcimwin32prov%2Fwin32-process%22%3EWin32_Process%20class%3C%2FA%3E%20to%20execute%20commands%20over%20the%20network.%20This%20behavior%20would%20generate%20something%20similar%20to%20this%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_13-1585348968130.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180086i8295A7D4FDA254DB%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_13-1585348968130.png%22%20alt%3D%22Cyb3rWard0g_13-1585348968130.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EWe%20can%20use%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2Fjoinoperator%3Fpivots%3Dazuredataexplorer%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2Fjoinoperator%3Fpivots%3Dazuredataexplorer%22%3EKQL%20and%20its%20JOIN%20operator%20%3C%2FA%3Eto%20look%20for%20a%20similar%20behavior%20without%20filtering%20on%20the%20parent%20process%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3Ewmiprvse.exe.%20%3C%2FSTRONG%3EWe%20can%20use%20events%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fauditing%2Fevent-4624%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fauditing%2Fevent-4624%22%3E4624%20(An%20account%20was%20successfully%20logged%20on)%3C%2FA%3E%20and%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fauditing%2Fevent-4688%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fauditing%2Fevent-4688%22%3E4688%20(A%20New%20process%20has%20been%20created)%3C%2FA%3E%20from%20the%20%3CCODE%20class%3D%22markup--code%20markup--p-code%22%3EMicrosoft-Windows-Security-Auditing%3C%2FCODE%3E%20event%20provider.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EUse%20the%20following%20query%20and%20run%20it%20in%20log%20analytics%20as%20shown%20below%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%20class%3D%22graf%20graf--pre%22%3Eprerecorded_CL%3CBR%20%2F%3E%7C%20extend%20a%3Dparse_json(Message)%3CBR%20%2F%3E%7C%20where%20a.event_id%20%3D%3D%204624%20and%20a.event_data.LogonType%20%3D%3D%203%20and%20a.event_data.TargetUserName%20!endswith%20%22%24%22%3CBR%20%2F%3E%7C%20project%20path_s%2C%20TargetLogonId%3Dtostring(a.event_data.TargetLogonId)%3CBR%20%2F%3E%7C%20join%20kind%3D%20inner%3CBR%20%2F%3E(%3CBR%20%2F%3E%20%20prerecorded_CL%3CBR%20%2F%3E%20%20%7C%20extend%20b%3Dparse_json(Message)%3CBR%20%2F%3E%20%20%7C%20where%20b.event_id%20%3D%3D%204688%20and%20b.event_data.TargetLogonId%20!%3D%20%220x3e4%22%3CBR%20%2F%3E%20%20%7C%20project%20ParentProcessName%3Db.event_data.ParentProcessName%2C%3CBR%20%2F%3E%20%20%20%20NewProcessname%3Db.event_data.NewProcessName%2C%3CBR%20%2F%3E%20%20%20%20CommandLine%3Db.event_data.CommandLine%2C%3CBR%20%2F%3E%20%20%20%20TargetLogonId%3Dtostring(b.event_data.TargetLogonId)%3CBR%20%2F%3E)%3CBR%20%2F%3Eon%20TargetLogonId%3CBR%20%2F%3E%7C%20project-away%20TargetLogonId%2C%20TargetLogonId1%3C%2FPRE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EAs%20you%20can%20see%20in%20the%20image%20below%2C%20that%20query%20got%20some%20hits%20from%20a%20few%20datasets%20that%20were%20created%20after%20emulating%20adversaries%20using%20WMI%20and%20Powershell%20Remoting%20to%20execute%20commands%20over%20the%20network%20%3Abow_and_arrow%3A%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CFIGURE%20class%3D%22graf%20graf--figure%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Cyb3rWard0g_14-1585348986881.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180087iDD131E7107EF7331%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Cyb3rWard0g_14-1585348986881.png%22%20alt%3D%22Cyb3rWard0g_14-1585348986881.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3EThat%E2%80%99s%20it%20for%20this%20first%20part!%20I%20hope%20you%20enjoyed%20it%20and%20found%20the%20design%20and%20deployment%20of%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%20helpful.%20In%20the%20next%20post%2C%20I%20will%20show%20you%20how%20to%20deploy%20additional%20resources%20along%20with%20an%20Azure%20Sentinel%20solution%20to%20focus%20on%20a%20few%20use%20cases%20that%20go%20beyond%20just%20using%20the%20Log%20Analytics%20features.%20I%20want%20to%20make%20sure%20%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%3C%2FSTRONG%3E%20also%20allows%20the%20exploration%20of%20other%20capabilities%20provided%20by%20Azure%20Sentinel.%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20class%3D%22graf%20graf--p%22%3E%3CSTRONG%20class%3D%22markup--strong%20markup--p-strong%22%3ESentinel2Go%20Link%3A%3C%2FSTRONG%3E%20%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%22%3Ehttps%3A%2F%2Fgithub.com%2Fhunters-forge%2FBlacksmith%2Ftree%2Fazure%2Ftemplates%2Fazure%2FSentinel2Go%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--p%22%3E%3CSTRONG%3EAzure%20Log%20Analytics%20API%20Scripts%20(POC)%3C%2FSTRONG%3E%3A%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId-622056522%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%20id%3D%22toc-hId-622056518%22%3E%26nbsp%3B%3C%2FH4%3E%0A%3CH4%20class%3D%22graf%20graf--h4%22%20id%3D%22toc-hId--1185397941%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%20id%3D%22toc-hId--1185397945%22%3EAdditional%20Large%20Open%20Datasets%20to%26nbsp%3Btest%3A%3C%2FH4%3E%0A%3CUL%20class%3D%22postList%22%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2Fmordor%2Ftree%2Fmaster%2Fdatasets%2Flarge%2Fwindows%2Fapt3%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fhunters-forge%2Fmordor%2Ftree%2Fmaster%2Fdatasets%2Flarge%2Fwindows%2Fapt3%22%3Ehttps%3A%2F%2Fgithub.com%2Fhunters-forge%2Fmordor%2Ftree%2Fmaster%2Fdatasets%2Flarge%2Fwindows%2Fapt3%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fmitre%2Fbrawl-public-game-001%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fmitre%2Fbrawl-public-game-001%22%3Ehttps%3A%2F%2Fgithub.com%2Fmitre%2Fbrawl-public-game-001%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Farxiv.org%2Fpdf%2F1903.02460.pdf%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Farxiv.org%2Fpdf%2F1903.02460.pdf%22%3Ehttps%3A%2F%2Farxiv.org%2Fpdf%2F1903.02460.pdf%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%20class%3D%22graf%20graf--li%22%3E%3CA%20class%3D%22markup--anchor%20markup--li-anchor%22%20href%3D%22https%3A%2F%2Fdata.mendeley.com%2Fdatasets%2Fzh3wnddzxy%2F2%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdata.mendeley.com%2Fdatasets%2Fzh3wnddzxy%2F2%22%3Ehttps%3A%2F%2Fdata.mendeley.com%2Fdatasets%2Fzh3wnddzxy%2F2%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH3%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId-1173032173%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%20id%3D%22toc-hId-1173032169%22%3E%26nbsp%3B%3C%2FH3%3E%0A%3CH2%20class%3D%22graf%20graf--h3%22%20id%3D%22toc-hId--763505009%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%20id%3D%22toc-hId--763505013%22%3EReferences%3C%2FH2%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fmordordatasets.com%2Fintroduction%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fmordordatasets.com%2Fintroduction%22%3Ehttps%3A%2F%2Fmordordatasets.com%2Fintroduction%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Ffaq%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Ffaq%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Ffaq%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fterminology%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fterminology%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fterminology%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-platform%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-platform%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-platform%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources%23custom-sources%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources%23custom-sources%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources%23custom-sources%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Foverview%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Foverview%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-as-code%2Fba-p%2F1131928%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%20data-href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-as-code%2Fba-p%2F1131928%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-as-code%2Fba-p%2F1131928%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Fmanagement%2Foverview%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolutions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolutions%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolutions%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fazuremarketplace.microsoft.com%2Fen-us%2Fmarketplace%2Fapps%2FMicrosoft.SecurityOMS%3Ftab%3DOverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fazuremarketplace.microsoft.com%2Fen-us%2Fmarketplace%2Fapps%2FMicrosoft.SecurityOMS%3Ftab%3DOverview%22%3Ehttps%3A%2F%2Fazuremarketplace.microsoft.com%2Fen-us%2Fmarketplace%2Fapps%2FMicrosoft.SecurityOMS%3Ftab%3DOverview%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fazure-sentinel%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fazure-sentinel%2F%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fazure-sentinel%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fmonitor%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fmonitor%2F%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fpricing%2Fdetails%2Fmonitor%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-azure_event_hubs.html%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-azure_event_hubs.html%22%3Ehttps%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Flogstash%2Fcurrent%2Fplugins-inputs-azure_event_hubs.html%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fservices%2Fevent-hubs%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fservices%2Fevent-hubs%2F%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fservices%2Fevent-hubs%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fgithub.com%2Fyokawasa%2Flogstash-output-azure_loganalytics%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fgithub.com%2Fyokawasa%2Flogstash-output-azure_loganalytics%22%3Ehttps%3A%2F%2Fgithub.com%2Fyokawasa%2Flogstash-output-azure_loganalytics%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%3CA%20class%3D%22markup--anchor%20markup--p-anchor%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22graf%20graf--p%22%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FFIGURE%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1260191%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20this%20post%2C%20I%20show%20you%20how%20to%20use%20ARM%20templates%20to%20deploy%20an%20Azure%20Sentinel%20solution%20and%20ingest%20pre-recorded%20datasets%20via%20a%20python%20script%2C%20Azure%20Event%20Hubs%20and%20a%20Logstash%20pipeline.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1260191%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Event%20Hubs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDetection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHunting%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELogstash%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPrerecorded%20datasets%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EThreat%20Hunting%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1262098%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1262098%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F452%22%20target%3D%22_blank%22%3E%40Robert%20Woods%3C%2FA%3E%26nbsp%3B%3A%20My%20experience%20is%20that%20the%20gap%20is%20using%20KQL%20for%20writing%20alert%20rules.%20A%20few%20resources%20that%20can%20help%20in%20this%20regard%20are%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EStart%20learning%20how%20to%20write%20rules%20in%20the%20webinar%20dedicated%20to%20this%20topic%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs%2521AnEPjr8tHcNmghhrDiXV1NeTZCZI%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EDeck%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmghlWrlBCPKwT5WTT%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FpJjljBT4ipQ%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EYou%20also%20find%20useful%20those%20blog%20posts%20which%20elaborate%20on%20the%20topic%3A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-correlation-rules-active-lists-out-make-list-in%2Fba-p%2F1029225%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EAzure%20Sentinel%20correlation%20rules%3A%20Active%20Lists%20out%3B%20make_list()%20in%2C%20the%20AAD%2FAWS%20correlation%20example%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-correlation-rules-the-join-kql-operator%2Fba-p%2F1041500%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EAzure%20Sentinel%20correlation%20rules%3A%20the%20join%20KQL%20operator%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fimplementing-lookups-in-azure-sentinel-part-1-reference-files%2Fba-p%2F1091306%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EImplementing%20Lookups%20in%20Azure%20Sentinel%20part%20%231%3A%20reference%20files%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusing-kql-functions-to-speed-up-analysis-in-azure-sentinel%2Fba-p%2F712381%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3EUsing%20KQL%20functions%20to%20speed%20up%20analysis%20in%20Azure%20Sentinel%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1267933%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1267933%22%20slang%3D%22en-US%22%3E%3CP%3EAmazing%20post!%20Thanks%20for%20sharing!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1262488%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20Sentinel%20To-Go%3A%20Sentinel%20Lab%20w%2F%20Prerecorded%20Data%20%3Asmiling_face_with_horns%3A%3C%2Fimg%3E%20%26amp%3B%20a%20Custom%20Logs%20Pipe%26nbsp%3Bvia%20ARM%20Templ%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1262488%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20morning%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F152270%22%20target%3D%22_blank%22%3E%40Yaniv%20Shmulevich%3C%2FA%3E%20%2C%20regarding%20the%20script%20never%20reaching%20the%20POST-AnalyticsData%20line%2C%20I%20tested%20it%2C%20and%20it%20does.%20I%20tested%20it%20with%20a%20small%20and%20large%20file%20and%20they%20both%20made%20it%20to%20the%20Log%20Analytics%20workspace.%20I%20opened%20a%20GitHub%20issue%20here%20to%20continue%20the%20conversation%20and%20do%20some%20testing%20together%20%3A)%3C%2Fimg%3E%20Thank%20you%20for%20the%20feedback.%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%2Fissues%2F1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FCyb3rWard0g%2Fazure-loganalytics-api-clients%2Fissues%2F1%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft
header-main.png

 

Recently, I started working with Azure Sentinel, and as any other technology that I want to learn more about, I decided to explore a few ways to deploy it. I got a grasp of the basic architecture and got more familiarized with it. As a researcher, I also like to simplify deployments in my lab environment and usually look for ways to implement the infrastructure I work with as code. Therefore, I started to wonder if I could automate the deployment of an Azure Sentinel solution via a template or a few scripts. Even though, it made sense to expedite the deployment of the solution, I realized I still did not have data or other resources to play with. Then, I wondered If I could integrate the deployment of an Azure Sentinel instance and other resources through the same scripts or templates covering different scenarios.

 

In the end, this approach allows me to also share the process with others in the community in a more practical way.

 

This post is part of a four-part series where I will show you how to deploy your own Azure Sentinel solution in a lab environment via Azure Resource Management (ARM) templates along with a custom logs ingestion pipeline to consume pre-recorded datasets and other resources such as network environments for research purposes.

 

In this post, I show you how to use ARM templates to deploy an Azure Sentinel solution and ingest pre-recorded datasets via a python script, Azure Event Hubs and a Logstash pipeline.

 

The other parts of this series can be found in the following links:

 

What is Azure Sentinel?

Microsoft Azure Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution. An Azure service that empowers organizations to bring disparate data sources from resources hosted both on-premises and in multiple clouds and be able to detect, investigate and respond to threats.

 

If you want to learn more about Azure Sentinel, I would recommend to explore this Microsoft Azure document page. Also, if you want to know what you can do with it, make sure you read the articles available in the Microsoft Tech Community Sentinel blog and take a look at these awesome webinars.

Deploying Azure Sentinel

Technically, all we need to do to deploy an Azure Sentinel solution is:

  • Create a Log Analytics Workspace: Azure Sentinel leverages the Azure Monitor Log Analytics workspace to store the data it collects..
  • Enable Azure Sentinel: This is enabled on the top of the workspace.

That basic set up allows you explore all the main features of Azure Sentinel as well as preloaded out-of-the-box resources such as queries, visualizations, response playbooks, and notebooks. You could also upload other resources and even enable data connectors in Azure Sentinel via code. Javier Soriano blogged about it in this post, and it is a great reference for production deployments.

One of the things I wanted to do different for this post was execute Azure Sentinel On-boarding steps, but in a declarative way with Azure Resource Manager (ARM) templates without having to run PowerShell commands. 

 

Azure Resource Manager (ARM) Templates?

 

To implement infrastructure as code for your Azure solutions, use Azure Resource Manager templates. The template is a JavaScript Object Notation (JSON) file that defines the infrastructure and configuration for your project. The template uses declarative syntax, which lets you state what you intend to deploy without having to write the sequence of programming commands to create it.

The Azure Resource Manager is the deployment and management service for Azure and below you can see some of the ways you could interact with it.

 

https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/overviewhttps://docs.microsoft.com/en-us/azure/azure-resource-manager/management/overview

 

A few things that I like about ARM templates are the orchestration capabilities to deploy resources in parallel which makes it faster than serial deployments, and also the feature to track deployments via the Azure portal.

 

https://docs.microsoft.com/en-us/azure/azure-resource-manager/templates/overview#why-choose-resource-manager-templateshttps://docs.microsoft.com/en-us/azure/azure-resource-manager/templates/overview#why-choose-resource-manager-templates

 

Additional Reading

 

On-boarding Azure Sentinel with ARM Templates

 

Now that we know a little bit more about Azure Resource Manager services, we are ready to deploy Azure Sentinel. One document that I recommend to get familiar with to learn more about Azure resources mapped to ARM template resource types is this one. In this section, we are going to deploy a Log Analytics workspace and enable Azure Sentinel. Remember that I provide the template for you so that you can follow along.

1. Deploying a Log Analytics Workspace ARM Template

 

A Log Analytics workspace can be found under the Microsoft.OperationalInsights resource types as Microsoft.OperationalInsights/workspaces

 

{
"name": "string",
"type": "Microsoft.OperationalInsights/workspaces",
"apiVersion": "2015-11-01-preview",
"location": "string",
"tags": {},
"properties": {
"sku": {
"name": "string"
},
"retentionInDays": "integer"
},
"resources": []
}

 

I created an initial template with some parameters to make it modular for anyone to use. This is the initial template:

 

 

2. Enabling Azure Sentinel ARM Template

 

Next, I needed to define the Azure Sentinel solution and enable it on the top of the Log Analytics workspace. You can do it with a resource type found under the Microsoft.OperationsManagement resource types as Microsoft.OperationsManagement/solutions .

 

{
"name": "string",
"type": "Microsoft.OperationsManagement/solutions",
"apiVersion": "2015-11-01-preview",
"location": "string",
"tags": {},
"plan": {
"name": "string",
"publisher": "string",
"promotionCode": "string",
"product": "string"
},
"properties": {
"workspaceResourceId": "string",
"containedResources": [
"string"
],
"referencedResources": [
"string"
]
}
}

 

I added that to our initial ARM template and this is the final result:

 

 

That’s it! You can download it and use it for the next steps.

Executing ARM Templates

 

There are a few ways to execute ARM templates, and it all depends on how comfortable you are with the Azure portal and Azure tool-kits (e.g. Azure CLI)

Prerequisites

  • An active Azure Subscription: If you don’t have one, create a free account. You might be eligible for some free credits for the first 30 days.
  • A Resource Group: A container that holds related resources for an Azure solution. You can use an existing one, but if this is your first time playing with Azure resources, you can create one following these instructions. You can also do it while deploying and ARM template via the Azure portal.

Option 1: Using Azure CLI

 

If you want to use one command to deploy an ARM template, then this option is for you. The Azure command-line interface (CLI) is Microsoft’s cross-platform command-line experience for managing Azure resources. It can be installed in Windows, macOS and Linux environments. In addition, there is a PowerShell version of it and also an interactive, authenticated, browser-accessible option known as the Azure Cloud Shell.

 

We can start using Azure CLI and create a Resource Group if you have not done it yet. Run the following command to create one in a specific location:

 

az group create --location eastus --resource-group AzSentinelDemo

 

Next, you can run the following command to execute the ARM template:

 

az deployment group create --name AzSentinelDeploy --resource-group AzSentinelDemo --template-file <ARM Template name>.json --parameters workspaceName=AzSentinelWS
  • az deployment group create: Start a deployment
  • --name : Name of your deployment
  • --resource-group: Name of the Azure Resource group
  • --template-file : Template that I put together for this deployment.
  • --parameters : Deployment parameter values (key=value). Provide a name for your Log Analytics workspace. The name must be globally unique across all Azure subscriptions. I take care of that for you in the template by adding a unique string after the name you provide.

 

Track your deployment: Azure Portal>Resource Group Name>Deployments

 

first-demo-deployment-one.png

 

first-demo-deployment-two.png

 

That’s it! once your deployment completes, you will be able to access the main Azure Sentinel interface. Before we do that, let me show you another way to execute our ARM template.

Option 2: Using Azure Portal


It takes a few more clicks to do it via the Azure portal, but it is easy to follow:

  • Go to https://portal.azure.com/ , click on the "Create a resource” option on the top left of your screen to create resources, and search for "Template Deployment".

 

create-resource-search-highlight.png

 

  • Choose: “Build your own template in the editor

 

create-resource-build-your-own.png

 

  • Upload the template we put together.

 

azure-resource-load-file.png

 

  • Once the template is uploaded, you will see the parameters and resources sections get populated. Click save.

 

azure-rsource-file-loaded.png

 

  • Next, you need to set your subscription and resource group names. As you can see in the image below, you can directly create an Azure Resource Group if you don’t have one yet. Click on Review to validate the template and finally create to deploy your resources.

 

azure-resource-azsentinel-parameters.png

 

Cyb3rWard0g_0-1601586094092.png

 

  • Then, you can track the deployment of your Azure Sentinel resources by going to Azure Portal > Resource Group Name > Deployments

 

Cyb3rWard0g_0-1601586332219.png

 

That’s it! once your deployment completes, you will be able to access the main Azure Sentinel interface.

Accessing Azure Sentinel

 

  • Search for “Azure Sentinel

 

Cyb3rWard0g_0-1601586504213.png

 

  • Select the Azure Sentinel workspace that you just created.

 

Cyb3rWard0g_1-1601586555179.png

 

You will be taken to the main Azure Sentinel interface. That was easy right?

 

Cyb3rWard0g_2-1601586637785.png

 

Wait, what?


Why do I have to do all that with ARM templates when I can just follow these instructions and with a few clicks I can deploy one too?

 

Deploying the solution while working in a lab environment is not enough. You need to have other resources and data to start exploring and learning about all the capabilities Azure Sentinel provides. That will take more than just a few clicks. What if we can take the ARM template that we just used and run other nested templates in parallel to deploy other resources and even ingest pre-recorded data for additional research?

Enter Azure Sentinel To-Go !

 

Cyb3rWard0g_0-1601587751987.png

 

Azure Sentinel2Go is an open source project developed to expedite the deployment of an Azure Sentinel lab along with other Azure resources and a data ingestion pipeline to consume pre-recorded datasets for research purposes.

 

Azure Sentinel2Go is part the Blacksmith project 

 

The Blacksmith project focuses on providing dynamic easy-to-use templates for security researches to model and provision resources to automatically deploy applications and small networks in the cloud.

 

Azure Sentinel2Go is a work in progress, and I welcome feedback on what it is that you would like to see being deployed along with an Azure Sentinel solution and datasets you would like to work with in your lab environment.

Azure Sentinel + Custom Log Pipeline

 

One of the features that I have noticed security analysts get interested the most while using Azure Sentinel for the first time is the Log Analytics capabilities. Log Analytics is the primary tool in the Azure portal for writing log queries written in Kusto Query Language (KQL) to quickly retrieve, consolidate, and analyze security events. Therefore, I decided to find a way for researchers to learn about KQL with pre-recorded datasets.

 

Fortunately, the Log Analytics workspace allows the collection of custom logs via its HTTP Data Collector API. If you want to learn how to do it with code, there are some basic examples in Azure docs for Powershell, C# and Python.

Data Ingestion Pipeline Designs


In this section I will share a few of my favorite ways to send pre-recorded datasets to a Log Analytics workspace custom log table.

1) Python Script -> Log Analytics Workspace

 

Cyb3rWard0g_12-1585348389443.png

 

This is one of the simplest ways to send data directly to a log analytics workspace. I took the basic example available here, and extended it a little bit to be able to read from a JSON file or a folder, show a progress bar, and send smaller sized chunks of 5MB per POST request. Make sure you read the Data Limits while using a similar approach. I also extended the PowerShell script available and created a proof of concept here.

 

The script is available here and all the information you will need from the log analytics workspace can be found in Azure Portal>Log Analytics Workspace>Advanced Settings.

 

Cyb3rWard0g_13-1585348408886.png

 

Next, we need a data sample for this exercise. Therefore, the project comes with a few data samples in this folder. Download the dataset-sample-small.tar.gz to your local computer and decompress it.

 

tar -xzvf dataset-sample-small.tar.gz

 

Next, send it over by running these commands in your local computer:

 

python3 ala-python-data-producer.py -w <WorkspaceID> -k <SharedKey> -l "onesample" -f dataset-sample-small.json -v

 

Once it completes go to your Azure Sentinel interface and click on Logs. You can see that there are no events yet. It usually takes from 5–10 mins.

 

Cyb3rWard0g_0-1601587031471.png

 

You can see a new table under customs logs with the event schemas. Remember that not every event will have the same schema. Make sure you understand the schema of your events before running queries.

 

Cyb3rWard0g_15-1585348441445.png

 

Based on the event schemas, we can run the following query to see what events we are working with:

 

onesample_CL
| summarize count() by winlog_channel_s, winlog_event_id_d, winlog_task_s

 

Cyb3rWard0g_16-1585348455615.png

 

That’s it! This is a very practical way to ingest custom logs, but might not scale with larger files or hundreds of files in a loop. Therefore, I wanted to also provide another option that would allow me to send events to a more robust pipeline and let it handle the whole process. This is a proof of concept and works very well in a lab environment.

2) Azure Event Hubs -> Logstash -> Log Analytics


I like to use existing tools that are proven to work at scale and this is not the exception. TL;DR — I use Kafkacat to read json files stored locally and send them over to an Azure Event Hub. Next, Logstash reads them from Azure Event Hub, and sends them over to a Log Analytics workspace.

 

Cyb3rWard0g_0-1585348612569.png

 

In more details the following is happening in the image above:

  • First, I use Kafkacat in Producer mode to read contents of a JSON file and send them over to a Kafka server. Kafkacat is a generic non-JVM producer and consumer for Apache Kafka.
  • Instead of a Kafka server, I use Azure Event Hubs with Kafka features enabled to receive and store events from Kafkacat. Azure Event Hubs is a server-less big data streaming platform and event ingestion service.
  • Next, I use a Linux VM with Logstash installed as a docker container to read events from the Azure Event Hub. Logstash is an open source data collection engine with real-time pipelining capabilities.
  • Finally, I use the same Logstash server to send events collected from the Azure Event Hub to the Azure Sentinel’s workspace for further analysis.

I already provide the following configurations as part of the Azure Sentinel2Go project.

 

Event Hub -> Logstash Conf

This is the Logstash input config file to consume events from an Azure Event Hub. The plugin used is the Logstash Azure Event Hubs input plugin.

 

input {
azure_event_hubs {
event_hub_connections => ["${EVENTHUB_CONNECTIONSTRING}"]
threads => 2
initial_position => "end"
#codec => "json"
}
}

 

I do not use the input codec => "json" property because I do not want to unpack the event Message field and exceed the max number (500) of custom fields per data type in the Log Analytics workspace.

 

Logstash Conf -> Log Analytics Workspace

 

This is the Logstash output config file to send the events that it collects from the Azure Event Hub to a Log Analytics workspace. The plugin used is the Azure Log Analytics output plugin for Logstash

developed by Microsoft.

 

output {
   microsoft-logstash-output-azure-loganalytics {
      workspace_id => "${WORKSPACE_ID}"
      workspace_key => "${WORKSPACE_KEY}"
      custom_log_table_name => "prerecorded"
      plugin_flush_interval => 5
   }
   #stdout { codec => rubydebug }
}

 

ARM Template Deployment

 

One thing I added to the Azure Sentinel2Go repository is a “Deploy to Azure” badge used on Azure quick-start templates to upload the ARM template directly to the Azure portal. Very convenient! You need to go to Azure-Sentinel2Go > grocery-list > custom-log-pipeline and click on the "Deploy to Azure" badge to deploy an Azure Sentinel along with a custom logs pipeline:

 

Cyb3rWard0g_0-1596328911451.png

 

You will be taken to the interface to set deployment parameters. Set the Deploy Custom Logs Pipeline parameter to Logstash-EventHub. One thing to pay attention to is the virtual machine size. If you are in westus, you need to switch it to Standard_A3 . Also, make sure you set the AllowedIPAddresses parameter to restrict access to the Logstash box. Add your company or your house Public IP address.

 

Cyb3rWard0g_0-1588783829191.png

 

Monitor your deployment. It should take around 8–10 minutes.

 

Cyb3rWard0g_3-1585348665121.png

 

Once it completes, you should be able to send prerecorded data from your local computer to the Azure Event Hub.

 

Sending events to the Azure Event Hub

 

First, create a local Kafkacat configuration file to define a few properties to be able to access the Azure Event Hub. I created one for you

 

You will need to get the following values and paste them in the config file.

  • Event Hub namespace: Get it from the Event Hub resource.
  • Event Hub Connection String: You can get it following these steps.

 

Second, we need a sample dataset to send over to our Azure Event Hub. We can use the same dataset we used earlier with the Python script.

 

Next, in your local computer, run Kafkacat in Producer mode as shown below. 

 

kafkacat -b <EVENTHUB-NAMESPACE>.servicebus.windows.net:9093 -t <EVENTHUB-NAME> -F <KAFKACAT-FILE>.conf -P -l dataset-sample.json
  • -b : Bootstrap broker(s) (host[:port]). Your Event Hub Namespace
  • -t : Topic to produce/send events to. The name of you Event Hub.
  • -F : Read configuration properties from the Kafkacat.conf file.
  • -P : Producer Mode : Produce/Send events.
  • -l : Send messages from a file. Pre-recorded dataset.

 

Once you run that command, you can check the events flowing through the Azure Event Hub. Go to Azure Portal > Resource Group Name > Event Hub Namespace and filter the Show Metrics view to show Messages only. It might take a few minutes for the view to update.

 

Cyb3rWard0g_4-1585348736789.png

 

The Azure Sentinel view also will take a a few mins to update.

 

Cyb3rWard0g_1-1588784274743.png

 

Explore the Custom Logs

 

As you already know, click on Logs (Log Analytics) to explore the custom logs and their schema. One thing to remember is that the events flowing through this pipeline are packed inside of the Message field. As I mentioned before, this is to avoid exceeding the max number (500) of custom fields per data type in case you send a lot of events with different schemas.

 

Cyb3rWard0g_2-1588784483863.png

 

You can unpack the Message field and get to specific nested fields with the Kusto Query function parse_json(). This function interprets a string as a JSON value and returns the value as dynamic . 

 

prerecorded_CL
| extend m=parse_json(Message)
| summarize count() by EventID=tostring(m.winlog.event_id),EventProvider=tostring(m.winlog.channel),Task=tostring(m.winlog.task)

 

Cyb3rWard0g_7-1585348820210.png

 

Remember that not every event will have the same schema. Make sure you understand the schema of your events before running queries.

(Optional) Loading Pre-Recorded Datasets

 

Azure Sentinel2Go also comes with the option to load pre-recorded datasets right at deployment time from the Mordor project. It leverages the same Logstash VM for the data ingestion. You do not have to send anything from your local computer. The data from mordor is downloaded and imported all via ARM templates.

 

Cyb3rWard0g_0-1588789915151.png

Downloading & Decompressing Mordor Datasets

 

I use the following commands to download and decompress all small mordor datasets. The commands are part of the deployment and are executed inside of the Linux VM when you choose to add the item "mordor-small-datasets" to the Add to cart parameter while deploying Azure Sentinel2Go. You do not have to run anything in your local computer.

 

git clone https://github.com/OTRF/mordor.git
cd mordor/datasets/small/
find . -type f -name "*.zip" | grep -i 'host' | while read filename; do unzip -o -d /opt/logstash/datasets/ $filename; done;

 

If you choose to add the item "mordor-large-apt29" to your Add Mordor Dataset parameter while deploying Azure Sentinel2Go, the following commands are executed inside of the Linux VM:

 

git clone https://github.com/OTRF/mordor.git
cd mordor/datasets/large/apt29
find . -type f -name "*_manual.zip" -print0 | xargs -0 -I{} unzip {} -d /opt/logstash/datasets/

 

JSON files -> Logstash Conf

 

This is the additional Logstash input config to read all the JSON files. The plugin used is the Logstash File Input plugin.

 

input {
file {
path => "/usr/share/logstash/datasets/*.json"
start_position => "beginning"
sincedb_path => "/dev/null"
#codec => "json"
}
}

 

ARM Template Deployment

 

If you have resources running from the earlier deployment, I recommend to delete them (Lab environment). Similar to our previous deployment, go to Azure-Sentinel2Go > grocery-list > custom-log-pipeline. Select Logstash for the Deploy Custom Logs Pipeline parameter as shown below and add a mordor dataset to your cart (Add Mordor Dataset) . For this example, we are going to use the mordor-small-datasets scenario. Also, once again, make sure you set the AllowedIPAddresses parameter to restrict access to the Logstash box. Add your company or your house Public IP address.

 

Cyb3rWard0g_1-1601955211079.png

 

Monitor the deployment. It might take around 8–10 minutes for it to be done. When it is complete, go to your Azure Sentinel interface. Give it 2–3 mins for events to start showing. You will start getting thousands of events (300K+).

 

Cyb3rWard0g_0-1601956084887.png

 

What I do while I wait for all the events (200k+) to be ingested :) 

 

Cyb3rWard0g_11-1585348900875.png

 

Playing and exercising at my backyard with my dog Pedro while the horses watch and datasets get ingested.

Take advantage of the time you have and stretch a little bit! Take a break!

What can we do with the data?

 

We can do the same as before and explore a few events to understand the event schemas. Also, since those events were generated as part of the Mordor project, you could focus on datasets mapped to specific ATT&CK tactics and techniques. The project comes with a Navigator View for the specific platforms that it supports (Currently only Windows).

 

Cyb3rWard0g_12-1585348954272.png

 

Let’s Look for Potential Lateral Movement Techniques

 

One thing that I like to look for when looking for lateral movement techniques is processes created under logon sessions that were initially created as part of a network authentication event (Logon Type 3). One example can be adversaries leveraging the Windows Management Instrumentation (WMI) and Win32_Process class to execute commands over the network. This behavior would generate something similar to this:

 

Cyb3rWard0g_13-1585348968130.png

 

We can use KQL and its JOIN operator to look for a similar behavior without filtering on the parent process wmiprvse.exe. We can use events 4624 (An account was successfully logged on) and 4688 (A New process has been created) from the Microsoft-Windows-Security-Auditing event provider.

 

Use the following query and run it in log analytics as shown below:

 

prerecorded_CL
| extend a=parse_json(Message)
| where a.EventID == 4624 and a.LogonType == 3 and a.TargetUserName !endswith "$"
| project path_s, TargetLogonId=tostring(a.TargetLogonId)
| join kind= inner
(
prerecorded_CL
| extend b=parse_json(Message)
| where b.EventID == 4688 and b.TargetLogonId != "0x3e4"
| project ParentProcessName=b.ParentProcessName,
NewProcessname=b.NewProcessName,
CommandLine=b.CommandLine,
TargetLogonId=tostring(b.TargetLogonId)
)
on TargetLogonId
| project-away TargetLogonId, TargetLogonId1

 

As you can see in the image below, that query got some hits from a few datasets that were created after emulating adversaries using WMI and Powershell Remoting to execute commands over the network.

 

Cyb3rWard0g_1-1601956552431.png

 

 

That’s it for this first part! I hope you enjoyed it and found the design and deployment of Azure Sentinel2Go helpful. In the next post, I will show you how to deploy additional resources along with an Azure Sentinel solution to focus on a few use cases that go beyond just using the Log Analytics features. I want to make sure Azure Sentinel2Go also allows the exploration of other capabilities provided by Azure Sentinel.

 

 

Additional Large Open Datasets to test:

 

References

https://mordordatasets.com/introduction

https://docs.microsoft.com/en-us/azure/azure-monitor/faq

https://docs.microsoft.com/en-us/azure/azure-monitor/terminology

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-platform

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources#custom-sources

https://docs.microsoft.com/en-us/azure/sentinel/overview

https://techcommunity.microsoft.com/t5/azure-sentinel/deploying-and-managing-azure-sentinel-as-code/...

https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/overview

https://docs.microsoft.com/en-us/azure/azure-resource-manager/templates/overview

https://docs.microsoft.com/en-us/azure/azure-monitor/insights/solutions

https://azuremarketplace.microsoft.com/en-us/marketplace/apps/Microsoft.SecurityOMS?tab=Overview

https://azure.microsoft.com/en-us/pricing/details/azure-sentinel/

https://azure.microsoft.com/en-us/pricing/details/monitor/

https://www.elastic.co/guide/en/logstash/current/plugins-inputs-azure_event_hubs.html

https://azure.microsoft.com/en-us/services/event-hubs/

https://github.com/yokawasa/logstash-output-azure_loganalytics

https://docs.microsoft.com/en-us/azure/kusto/query/

 

24 Comments
Microsoft

This is awesome - Thanks for posting!!! 

Awesome Blogpost @Cyb3rWard0g :cool: Thank you for Sharing with the Community.

 

Super Contributor

Has anyone else had problems getting their sec ops team to adopt the Kusto query language? Pointing them to the Microsoft docs does not help. Any more robust training out there around Kusto and most common queried scenarios? I am personally embracing it but if the rest of my team ignores it then the tool isn't useful. They seem to want to be able to drill down without having to write custom queries for common scenarios...

Occasional Contributor

@Cyb3rWard0g  Hi! really cool stuff. I could not find the ala-python-data-producer.py file... I must have missed something here. Can you assist? thanks

Yaniv.

Microsoft

Hey @Yaniv Shmulevich , Yes I updated the post with a link to the project at the end of the post, and also while I show the scripts options. This is the link of the project where I host those scripts (Proof of concept) : https://github.com/Cyb3rWard0g/azure-loganalytics-api-clients . Thank you for the feedback! :)

Occasional Contributor

Hi @Cyb3rWard0g  thanks, found it :) . I decided to execute the ps script this time to ingest data. I ran it few times and nothing happened. I debugged it and I realized that it never reaches the Post-LogAnalyticsData (line187) command. I remarked it and put two lines at location 200,201:

  • $json_records_converted = $json_records | ConvertTo-Json
  • Post-LogAnalyticsData -customerId $WorkspaceId -sharedKey $WorkspaceSharedKey -body ([System.Text.Encoding]::UTF8.GetBytes($json_records_converted)) -logType $logType 

and it succeeded. I hope I am right here. anyway, it is the only option I succeeded to ingest data to log analytics.

thanks

Yaniv.

Microsoft

@Robert Woods : My experience is that the gap is using KQL for writing alert rules. A few resources that can help in this regard are:

 

Microsoft

Good morning @Yaniv Shmulevich , regarding the script never reaching the POST-AnalyticsData line, I tested it, and it does. I tested it with a small and large file and they both made it to the Log Analytics workspace. I opened a GitHub issue here to continue the conversation and do some testing together :) Thank you for the feedback. https://github.com/Cyb3rWard0g/azure-loganalytics-api-clients/issues/1

Microsoft

Amazing post! Thanks for sharing!

 

Super Contributor

I uploaded all the events using the PowerShell script provided but when I tried to run the sample query it fails stating that 'path_s' does not exist (which is true).  Any ideas why that would not have been loaded?

Microsoft

Hey @Gary Bushey , would you mind providing the sample query? Are referring to this one?

 

onesample_CL
| summarize count() by winlog_channel_s, winlog_event_id_d, winlog_task_s

 

Super Contributor

@Cyb3rWard0g this one:

 

prerecorded_CL
| extend a=parse_json(Message)
| where a.event_id == 4624 and a.event_data.LogonType == 3 and a.event_data.TargetUserName !endswith "$"
| project path_s, TargetLogonId=tostring(a.event_data.TargetLogonId)
| join kind= inner
(
prerecorded_CL
| extend b=parse_json(Message)
| where b.event_id == 4688 and b.event_data.TargetLogonId != "0x3e4"
| project ParentProcessName=b.event_data.ParentProcessName,
NewProcessname=b.event_data.NewProcessName,
CommandLine=b.event_data.CommandLine,
TargetLogonId=tostring(b.event_data.TargetLogonId)
)
on TargetLogonId
| project-away TargetLogonId, TargetLogonId1
Occasional Contributor

This is super valuable and most importantly comes with the data which the crucial for research, experimentation and learning. Kudos !  

Microsoft

Thank you very much for the feedback @knsw7 ! :) Happy to hear you find it useful!

Microsoft

@Sorcia25 . I deleted your comment by accident. This is what you have asked correct?

 

1.- Exist a process to inject data to other LogAnalitycs tables? for example AuditLogs, AzureActivity, OfficeActivity? Or the injected data in prerecorded_CL would be moved to those tables?

That is not possible at the moment. It will be a feature that will be open soon but for specific tables. I am waiting for that as well :)

 

1.- The data injected while the template run are all the data that will exist in the LogAnalitys WS? Or exist a process to inject fresh data day by day?

What do you mean with "inject fresh data day by day?" ? do you mean to inject Mordor datasets daily?

Senior Member

@Cyb3rWard0g - firstly, a huge thanks for putting this post together; it's helped cement some fundamental Sentinel concepts I was struggling to get a handle on.

 

One quick question; I've deployed the Sentinel2Go Azure Sentinel + Custom Log Pipeline template with the large mordor-large-apt29 dataset and the Logstat-EventHub pipeline.  This has given me 263,620 entries, and following a slight tweak to the syntax of your example (see below) I've created an Analytics Rule to create Incidents.

I thought I'd test Sentinel's Incident Investigation capabilities by creating a second Incident for the same computer/user so started looking closer at the Mordor dataset page only to find that none of the Hostnames match what I was expecting; instead of The Shire or Erabor environments I appear to have demvals.local.  Am I missing something really obvious here...?

 

 

prerecorded_CL
| extend a=parse_json(Message)
| where a.SourceName == "Microsoft-Windows-Security-Auditing"
| where a.EventID == 4624 and a.LogonType == 3 and a.TargetUserName !endswith "$"
| project path_s, Hostname=tostring(a.Hostname), TargetLogonId=tostring(a.TargetLogonId), TargetUserName=tostring(a.TargetUserName)
| join kind= inner
(
  prerecorded_CL
  | extend b=parse_json(Message)
  | where b.EventID == 4688 and b.TargetLogonId != "0x3e4"
  | project ParentProcessName=b.ParentProcessName,
    NewProcessname=b.NewProcessName,
    CommandLine=b.CommandLine,
    TargetLogonId=tostring(b.TargetLogonId),
    Hostname=tostring(b.Hostname),
    TargetUserName=tostring(b.TargetUserName)
)
on TargetLogonId
| project-away TargetLogonId, TargetLogonId1
| extend AccountCustomEntity = TargetUserName
| extend HostCustomEntity = Hostname
Microsoft

Hey @AndyHerb ! Very happy to hear that it was helpful to cover some of the basic concepts behind the infrastructure and deployments in a lab environment :) .

 

Thank you for sharing the query! Just to make sure I follow the last question. You deployed APT29 dataset and then you wanted to create a second incident by consuming other Mordor datasets right (small datasets) ? If so, yes. Mordor Shire has a different domain name. dmevals is for all ATT&CK evals deployments and datasets. One thing I am working on is the use of a script to transform mordor datasets to make them look as if they were created in any environment. It is still a proof of concept. I will be releasing soon.

 

Would you mind sharing how you created the investigation with the APT29 datasets? I would like to add that to the project as a reference. Thank you

Microsoft

hi nice article!! how do you install kafkacat . apt-get install 1.3.1 version but the -F flag is in the new versions? do you docker version? or build the executable? (i am using ubuntu in WSL 2)

Microsoft

Hey @cesarfong ! Thank you. Have you tried to build it? https://github.com/edenhill/kafkacat#requirements . Yeah old versions do not have that flag.

Microsoft

I use docker to run it
 
docker run -it --mount type=bind,source="<local path>",target="/app" --
network=host
edenhill/kafkacat:1.6.0 -b <name>.servicebus.windows.net:9093 -t <name2> -P -F /app/kafkacat.conf -l /app/dataset-sample-small.json
 
:)

Microsoft

Ahh niceeee! thank you @cesarfong . That works too :) I will make a note of that too. Thank you for sharing.

Microsoft

glad to help!!! :)

Senior Member

@Cyb3rWard0g - Using the KQL from your "Potential Lateral Movement" example I posted previously, I created an Analytic which ran every 5 hours over the last 5 days' worth of data - just so that I got a bunch of Incidents to look at, even though I appreciate they're really all the same event :smile:

 

Once that had created a few Incidents I drilled into Investigation, and discovered that Sentinel can show linked events (related to Computer and User in this case) and it was this feature which I wanted to be able to showcase.  Whilst I was able to fake it with a dummy Incident (see KQL below) I was hoping to be able to use some of the real data present in the Mordor data set, but couldn't easily work out how to capture that via KQL, as all the examples listed on the Mordor website didn't appear to be present in the dataset.

Dummy Incident for showcasing linked events

prerecorded_CL
| extend a=parse_json(Message)
| where a.Hostname == "NASHUA.dmevals.local"
| where a.TargetImage != @"C:\windows\System32\svchost.exe"
| where a.SourceName == "Microsoft-Windows-Security-Auditing"
| where a.SourcePort == 59914
| project Hostname=tostring(a.Hostname)
| extend HostCustomEntity = Hostname
Microsoft

Hey @AndyHerb thank you very much for the feedback and sharing the additional use cases. can you provide more details about "Whilst I was able to fake it with a dummy Incident (see KQL below) I was hoping to be able to use some of the real data present in the Mordor data set, but couldn't easily work out how to capture that via KQL, as all the examples listed on the Mordor website didn't appear to be present in the dataset."