Managing and monitoring your Microsoft Sentinel instance
Managing and monitoring our Microsoft Sentinel instance ensures that we are regularly reviewing and responding to any threats and taking any corrective action that may be required. Some of the methods available to manage and monitor Microsoft Sentinel are as follows:
- Microsoft Sentinel Overview screen: From the Microsoft Sentinel | Overview section, you can review a selection of alerts and metrics, such as recent incidents, events, and alerts over time, as shown in the following screenshot:
Figure 9.48: Microsoft Sentinel Overview screen
Here you can review events, alerts, usage, and metrics.
- Microsoft Sentinel logs: From the Microsoft Sentinel | Logs section, you can choose from a large number of built-in queries under Log Analytics workspaces and see information on things such as Applications and Azure Monitor, as shown in the following screenshot:
...