New Blog Post | Migrating content from traditional SIEMs to Azure Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-2662569%22%20slang%3D%22en-US%22%3ENew%20Blog%20Post%20%7C%20Migrating%20content%20from%20traditional%20SIEMs%20to%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2662569%22%20slang%3D%22en-US%22%3E%3CDIV%20id%3D%22tinyMceEditorAshleyMartin_0%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20id%3D%22tinyMceEditorAshleyMartin_1%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MSC19_microsoftInclusion_redmond_002-900x360.jpg%22%20style%3D%22width%3A%20900px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F304206i1D5249B98914CFEF%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22MSC19_microsoftInclusion_redmond_002-900x360.jpg%22%20alt%3D%22MSC19_microsoftInclusion_redmond_002-900x360.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2021%2F08%2F18%2Fmigrating-content-from-traditional-siems-to-azure-sentinel%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMigrating%20content%20from%20traditional%20SIEMs%20to%20Azure%20Sentinel%20%7C%20Microsoft%20Security%20Blog%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22x-hidden-focus%22%3EIn%20part%20two%20of%20this%20three-part%20series%2C%20we%20covered%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2021%2F08%2F03%2Fhow-to-manage-a-side-by-side-transition-from-your-traditional-siem-to-azure-sentinel%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Efive%20types%20of%20side-by-side%20security%20information%20and%20event%20management%20(SIEM)%20configurations%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ecommonly%20used%20during%20a%20long-term%20migration%20to%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fservices%2Fazure-sentinel%2F%23overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Azure%20Sentinel%3C%2FA%3E.%20For%20part%20three%2C%20we%E2%80%99ll%20be%20looking%20at%20best%20practices%20for%20migrating%20your%20data%20and%20detections%20while%20operating%20side-by-side%20with%20your%20on-premises%20SIEM%2C%20as%20well%20as%20ways%20to%20maximize%20Azure%20Sentinel%E2%80%99s%20powerful%20automation%20capabilities%20to%20streamline%20common%20tasks.%3C%2FP%3E%0A%3CP%20class%3D%22x-hidden-focus%22%3EThe%20information%20presented%20here%20is%20derived%20from%20experiences%20we%E2%80%99ve%20accumulated%20while%20assisting%20numerous%20customer%20migrations%2C%20as%20well%20as%20experiences%20gained%20by%20Microsoft%E2%80%99s%20own%20security%20operations%20center%20(SOC)%20in%20protecting%20our%20IT%20infrastructure.%20Typically%2C%20the%20migration%20to%20Azure%20Sentinel%20is%20undertaken%20in%20three%20phases%3A%20starting%20with%20data%2C%20then%20detection%20rules%2C%20and%20finally%20by%20automating%20workflows.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2662569%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Security%20Center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Sentinel%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20Security%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20365%20Defender%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft
 
 

MSC19_microsoftInclusion_redmond_002-900x360.jpg

Migrating content from traditional SIEMs to Azure Sentinel | Microsoft Security Blog

In part two of this three-part series, we covered the five types of side-by-side security information and event management (SIEM) configurations commonly used during a long-term migration to Microsoft Azure Sentinel. For part three, we’ll be looking at best practices for migrating your data and detections while operating side-by-side with your on-premises SIEM, as well as ways to maximize Azure Sentinel’s powerful automation capabilities to streamline common tasks.

The information presented here is derived from experiences we’ve accumulated while assisting numerous customer migrations, as well as experiences gained by Microsoft’s own security operations center (SOC) in protecting our IT infrastructure. Typically, the migration to Azure Sentinel is undertaken in three phases: starting with data, then detection rules, and finally by automating workflows.

0 Replies