Using Azure Sentinel To Monitor Service Availability

Copper Contributor

Hi Community.

 

Does anyone know if Azure Sentinel is able to monitor incidents relating to service availability?

I understand that Sentinel is a full-fledge SIEM/SOAR tool that is security focused.
I am wondering if it has the capability to monitor service availability for all Azure resources and services that operates at both control plane and data plane.

 

I'm looking for a solution in Azure that is able to achieve the same objective as AWS' Incident Manager that offers a single panel to view all incidents relating to security and availability.

 

I understand that we are able to ingest logs from any sources into Sentinel for monitoring purpose.

I just need to know if I can use a single console in Azure (e.g. Sentinel) to monitor both security and service availability incidents.

 

Appreciate some pointers.

 

Thank you!

 

4 Replies
Unfortunately, I couldn’t find any specific documentation on how to use a single console in Azure (e.g. Sentinel) to monitor both security and service availability incidents. However, you could write your own log queries and use them in both Sentinel alerts and Azure Monitor alerts
https://www.cloudsma.com/2020/04/overview-azure-monitor-sentinel-security-center/
Thank you Chandrasekhar_Arya
Please "Accept as Answer" if it helped so it can help others in community looking for help on similar topics.

@spurs23 

Seems no single interface at the moment but you may need to handle it under Azure Monitor, Log analytic workspace