User Profile
tal_rosler
Joined 7 years ago
User Widgets
Recent Discussions
Re: Burst of multiple reconnaissance commands could indicate initial activity after compromise
Hi ujjawalm , Those alerts are result of a known temporal error in our system caused Azure Security Center to trigger alerts that shouldn't be triggered. The issue was mitigated successfully - you shouldn’t get such alerts anymore. I am very sorry for the inconvenient it caused – please feel free to ignore those alerts. Thanks, Tal Rosler, Product Manager, Azure Security Center.2KViews0likes0CommentsRe: Analysis of host data detected a large number of system log files being removed
Hi ujjawalm , Those alerts are result of a known temporal error in our system caused Azure Security Center to trigger alerts that shouldn't be triggered. The issue was mitigated successfully - you shouldn’t get such alerts anymore. I am very sorry for the inconvenient it caused – please feel free to ignore those alerts. Thanks, Tal Rosler, Product Manager, Azure Security Center.993Views0likes1CommentRe: How to filter security events only from Event Hub and send to SIEM
Hi palchak , Your customer can use Microsoft Graph connector for QRadar to send Azure Security Center data easier to QRadar. Please read more details here: https://techcommunity.microsoft.com/t5/azure-security-center/accessing-azure-security-center-alerts-in-splunk-using-graph/ba-p/938228 Thanks, Tal Rosler, Azure Security Center.1.7KViews0likes0CommentsWelcome to the Azure Security Center community forum
Welcome to the Azure Security Center community forum! Join us to share questions, thoughts, and ideas about Azure Security Center and receive answers from the diverse Security Center community. Our community is here to assist you with any questions or challenges you may have. This forum is part of the Security Center community platforms, including the GitHub repository for sharing code, and a blog for keeping up-to-date with news and how-to-guides. Get involved in any of the following community platforms: Azure Security Center GitHub repository Azure Security Center Blog Features Suggestions To learn more about Azure Security Center, see the: Product description and introduction Security Center documentation Feel free to post any questions, comments, or requests here. Best regards, Azure Security Center team2.3KViews2likes0Comments
Recent Blog Articles
Defender CSPM enhances risk prioritization, remediation, and compliance for multicloud environments
New innovations in Defender CSPM reinforce our commitment to empowering security teams to better prioritize business-critical risks, accelerate multicloud compliance, and streamline risk remediation....4.8KViews2likes0CommentsSuppression rules for Azure Security Center alerts are now available in public preview
Suppression rules giving the ability to fine-tune Azure Security Center alerts by your organizations' specific needs and conditions, letting you suppress alerts that are triggered by known normal act...37KViews2likes0Comments