Azure Sentinel
Copied!
Home
Options
2,285
Pete Bryan on 10-07-2019 10:00 AM
2,418
ianhelle on 09-30-2019 08:27 AM
4,181
Ofer_Shezaf on 09-24-2019 11:30 PM
5,180
Ofer_Shezaf on 09-19-2019 02:11 PM
2,359
Ofer_Shezaf on 09-18-2019 02:00 AM
14.3K
Tiander Turpijn on 08-31-2019 02:58 PM
4,672
Ofer_Shezaf on 08-19-2019 01:43 PM
8,823
Ofer_Shezaf on 08-13-2019 11:53 PM
3,936
Ofer_Shezaf on 08-07-2019 02:30 AM
4,633
Ashwin_Patil on 07-31-2019 07:45 AM
2,336
Ofer_Shezaf on 07-22-2019 05:15 PM
2,909
Pete Bryan on 06-25-2019 08:27 AM
3,832
ianhelle on 06-17-2019 08:27 AM
3,675
Ashwin_Patil on 06-10-2019 07:44 AM
4,546
ianhelle on 06-05-2019 05:02 PM
3,449
Ashwin_Patil on 05-15-2019 07:00 AM
3,395
ianhelle on 05-13-2019 06:32 AM
2,788
Tim Burrell (MSTIC) on 05-01-2019 08:34 AM
4,165
ianhelle on 04-25-2019 05:11 PM
2,747
ianhelle on 04-22-2019 08:27 AM
8,920
ianhelle on 04-16-2019 08:22 AM
6,121
shainw on 04-11-2019 09:00 AM
Latest Comments
So in addition to adding a null return type for FromIP per @caiodaruizcorrea I also needed to add a null return type for Subject. After that, all worked successfully. Thanks everyone!
1 Likes
Thanks @caiodaruizcorrea that's very helpful
1 Likes
Hi @Stefan Simon, Thanks for the template.Just created the Playbook and noticed that in our case the Json schema didn't work.It is due to some of the message traces coming with a Null value under the FromIP.Worth adjusting your template so not just the ToIP but the FromIP can accept Null values:"Fro...
1 Likes
Hi Nicholas, I was wondering if you know how I can daisy chain collectors like in the timed youtube link (https://youtu.be/_mm3GNwPBHU?list=PLOhMGpMOPKRHPHCvzia3EE5OY5EkQRCuH&t=896) was presented by one of Microsoft's Sentinel guys called Ofer. I was able to install the CEF-Syslog Ubuntu server on-p...
0 Likes
Hi @KenSilver , @Mahesh0212 , I just tried to redo the playbook and all works well. Please check if you have correctly filled HTTP request and that it correctly returns O365 Message Trace in JSON format (you can do it in the Run History of the playbook).
0 Likes