Conversion of Existing SIEM(QRadar, Arcsight) rule to Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-1679594%22%20slang%3D%22en-US%22%3EConversion%20of%20Existing%20SIEM(QRadar%2C%20Arcsight)%20rule%20to%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1679594%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20key%20challenge%20which%20we%20are%20facing%20is%20to%20migrate%20existing%20SIEM(QRadar%2C%20ArcSight)%20solution%20use%20cases%20to%20Sentinel%20Use%20cases.%20We%20tried%20uncoder.io%20but%20even%20that%20is%20not%20helpful%20to%201%25.%20Please%20support%20if%20some%20one%20is%20having%20good%20way%20to%20execute%20it.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1687776%22%20slang%3D%22en-US%22%3ERE%3A%20Conversion%20of%20Existing%20SIEM(QRadar%2C%20Arcsight)%20rule%20to%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1687776%22%20slang%3D%22en-US%22%3EYou%20can%20convert%20only%20the%20queries.%20Use%20cases%20in%20ArcSight%20ESM%20or%20QRadar%20has%20to%20be%20rebuilt%20on%20Sentinel%20manually.%3C%2FLINGO-BODY%3E
New Contributor

The key challenge which we are facing is to migrate existing SIEM(QRadar, ArcSight) solution use cases to Sentinel Use cases. We tried uncoder.io but even that is not helpful to 1%. Please support if some one is having good way to execute it.  

3 Replies
You can convert only the queries. Use cases in ArcSight ESM or QRadar has to be rebuilt on Sentinel manually.

@vijayyadav351 You can also check places like SocPrime that have a repository of alert rules to see if the ones you need in your other system are present and then export those as Azure Sentinel rules.

@Cyb3rMonk but I am unable to convert query also. You mean using undecoder.io or there is other way available.