Introducing Azure Sentinel
Azure Sentinel is a modernized SIEM and Security Orchestration Automated Response (SOAR) that is built on Microsoft cloud technology. Azure Sentinel is a centralized SIEM solution that provides an intelligent robust life cycle to allow the collection of data, the detection of threats, the investigation of threats, and responses to incidents. Because Azure Sentinel is a cloud-built solution, the ease of setup and integration makes this service an extremely attractive and powerful service for your security needs, especially compared to a traditional SIEM, which typically requires massive amounts of infrastructure and storage to efficiently support the ongoing log collection and compute power to analyze data.
Creating the connection
To set up Azure Sentinel within Azure, follow these steps:
- Log in to https://portal.azure.com.
- Search for Azure Sentinel and open it.
- Click on Add or Connect Workspace.
- Select a workspace to connect to,...