Azure Sentinel
Azure Sentinel is your birds-eye view on centralized security data and events across an organization, using integrated AI for large-scale threat analysis and response.
It is Microsoft's cloud-based security information and events management (SIEM) and security orchestration, automation, and response (SOAR) tool; it provides security data aggregation, threat analysis, and response across public cloud and on-premises environments.
A SIEM solution collects security log data (security signaling) and examines this log data for patterns that could indicate an attack, then correlates event information to identify potentially abnormal activity. Finally, any issues are alerted and this automates responses and remediation. The following diagram illustrates this relationship:
Azure Sentinel provides the following core capabilities:
- Collects security data across an organization
- Detects threats...