Feb 16 2021 08:56 AM
Please I need help with a playbook for network fileshare monitoring as well as data access.
Feb 16 2021 09:27 AM
Feb 16 2021 09:42 AM
Feb 16 2021 11:30 AM
@gregg340 That would really depend on which file server you are using.
BTW, in Azure Sentinel speak, a playbook is an automated workflow that runs when an alert is created. You would want a data connector in this case.
I don't see any data connectors for file servers listed but if it can export its logs into either a Syslog or CEF format you can easily obtain the data. Otherwise a custom connector may need to be written to upload the data into Azure Sentinel.