Home

Default Sentinel Overview dashboard widgets indicate no data. Where is the query for the map?

%3CLINGO-SUB%20id%3D%22lingo-sub-391431%22%20slang%3D%22en-US%22%3EDefault%20Sentinel%20Overview%20dashboard%20widgets%20indicate%20no%20data.%20Where%20is%20the%20query%20for%20the%20map%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-391431%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20monitoring%20IIS%2C%20Apache%2C%20RDP%20servers%20that%20are%20accessible%20from%20the%20Internet.%20The%20default%20Sentinel%20Overview%20dashboard%20sometimes%20displays%20a%20little%20information%20in%20the%20map%2C%20but%20so%20far%20that%20has%20been%20limited%20to%20one%20country%20or%20region%20at%20a%20time.%20Thanks%20to%20the%20cesspool%20that%20is%20the%20Internet%2C%20I%20have%20plenty%20of%20data%20pertaining%20to%20recon%20from%20all%20over%20the%20world.%20Why%20would%20the%20map%20show%20only%20one%20location%3F%20Or%2C%20as%20it%20is%20today%2C%20be%20blank%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhere%20is%20there%20query%20that%20Sentinel%20uses%20to%20make%20the%20map%3F%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F100678i1751F50EA477B0D9%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22nodatainmap.png%22%20title%3D%22nodatainmap.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMaybe%20the%20time%20window%20is%20less%20than%20an%20hour...%3F%20During%20the%20past%20hour%20I%20had%20connections%20from%20IIS%20connection%20attempts%20from%20South%20Africa%20and%20Thailand%2C%20but%20none%20during%20the%20past%203%20minutes.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20what%20I've%20seen%20over%20the%20past%2024%20hours.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F100679iB3A35C5017A3436F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%2224hoursCountries.png%22%20title%3D%2224hoursCountries.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392079%22%20slang%3D%22en-US%22%3ERe%3A%20Default%20Sentinel%20Overview%20dashboard%20widgets%20indicate%20no%20data.%20Where%20is%20the%20query%20for%20the%20map%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392079%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F302813%22%20target%3D%22_blank%22%3E%40PeterSchawacker%3C%2FA%3E%26nbsp%3B%20this%20might%20be%20too%20obvious%2C%20but%20the%20map%20it%20centered%2C%20so%20if%20you%20use%20your%20mouse%20to%20drag%20the%20view%20to%20SA%20or%20Thailand%20or%20zoom%20out%20do%20they%20show%20up%3F%26nbsp%3B%20If%20not%20can%20you%20share%20your%20query%2C%20in%20case%20there%20is%20an%20issue%20with%20it%3F%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20click%20on%20the%20map%20(place%20cursor%20on%20the%20orange%20hotspot%20and%20click)%26nbsp%3B%20you%20should%20see%20the%20query%20used%3F%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20509px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F100850i2C473B9C9ADFADF9%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Annotation%202019-04-01%20193055.jpg%22%20title%3D%22Annotation%202019-04-01%20193055.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20just%20IIS%20logs%20and%20as%20a%20quick%20test%2C%20you%20can%20use%20an%20example%20of%3A%3C%2FP%3E%0A%3CDIV%3E%0A%3CDIV%3E%0A%3CPRE%3EW3CIISLog%0A%7C%20extend%20TrafficDirection%20%3D%20%22InboundOrUnknown%22%2C%20Country%3DRemoteIPCountry%2C%20Latitude%3DRemoteIPLatitude%2C%20Longitude%3DRemoteIPLongitude%20%20%0A%7C%20where%20isnotempty(MaliciousIP)%0A%7C%20summarize%20count()%20by%20TrafficDirection%2C%20%20MaliciousIP%20%2C%20RemoteIPCountry%20%20%3C%2FPRE%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-391955%22%20slang%3D%22en-US%22%3ERe%3A%20Default%20Sentinel%20Overview%20dashboard%20widgets%20indicate%20no%20data.%20Where%20is%20the%20query%20for%20the%20map%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-391955%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F302813%22%20target%3D%22_blank%22%3E%40PeterSchawacker%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%3A%20Is%20this%20something%20you%20can%20help%20with%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-481533%22%20slang%3D%22en-US%22%3ERe%3A%20Default%20Sentinel%20Overview%20dashboard%20widgets%20indicate%20no%20data.%20Where%20is%20the%20query%20for%20the%20map%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-481533%22%20slang%3D%22en-US%22%3EHello%3CBR%20%2F%3EI%20just%20started%20reading%20about%20sentinel%20and%20I%20would%20like%20to%20analyse%20IIS%20Logs%20in%20Sentinel.%3CBR%20%2F%3EWhat%20type%20of%20data%20connector%20should%20I%20use%20or%20how%20can%20I%20import%20IIS%20Logs%20%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I'm monitoring IIS, Apache, RDP servers that are accessible from the Internet. The default Sentinel Overview dashboard sometimes displays a little information in the map, but so far that has been limited to one country or region at a time. Thanks to the cesspool that is the Internet, I have plenty of data pertaining to recon from all over the world. Why would the map show only one location? Or, as it is today, be blank?

 

Where is there query that Sentinel uses to make the map?

nodatainmap.png

 

Maybe the time window is less than an hour...? During the past hour I had connections from IIS connection attempts from South Africa and Thailand, but none during the past 3 minutes. 

 

This is what I've seen over the past 24 hours.

 

24hoursCountries.png

4 Replies
Highlighted
Highlighted

@PeterSchawacker  this might be too obvious, but the map it centered, so if you use your mouse to drag the view to SA or Thailand or zoom out do they show up?  If not can you share your query, in case there is an issue with it? 

 

If you click on the map (place cursor on the orange hotspot and click)  you should see the query used?

Annotation 2019-04-01 193055.jpg

 

For just IIS logs and as a quick test, you can use an example of:

W3CIISLog
| extend TrafficDirection = "InboundOrUnknown", Country=RemoteIPCountry, Latitude=RemoteIPLatitude, Longitude=RemoteIPLongitude  
| where isnotempty(MaliciousIP)
| summarize count() by TrafficDirection,  MaliciousIP , RemoteIPCountry  

 

Highlighted
Hello
I just started reading about sentinel and I would like to analyse IIS Logs in Sentinel.
What type of data connector should I use or how can I import IIS Logs ?

Thanks
Highlighted

@Liventus 

 

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-iis-logs

 

Enable the collection (as per the above link) and Logs will transfer from any machine that has the Log Analytics agent and IIS into the workspace, for Sentinel or Log Analytics to query.