Deployment Creation/Deletion Alerts in Sentinel

Copper Contributor

I have deployment creation/deletion alerts created it Azure Monitor, but is there a way to create those alerts in Sentinel? I would like to have those alerts consolidated into Sentinel, rather than create them for each subscription in Monitor.

 

I have been unable to find pre-made templates or KQL queries to accomplish this.

2 Replies

Hey @matt45 

 

You can create alerts in Sentinel, within Sentinel they are called Analytics

 

You will need to connect the data to sentinel for the alerts depending on what items you want to monitor for in terms of creation/deletion

@BillClarksonAntill 

 

Thank you for your response! That's the issue I've been having; I have all the data connectors connected, but am unable to find a premade analytic rule or the KQL to write my own.