An introduction to Azure Sentinel Analytics
Azure Sentinel Analytics is where you set up rules to find issues with your environment. You can create various types of rules, each with its own configuration steps and niche for the types of abnormalities you are trying to detect.
Types of analytic rules
There are currently four types of rules: scheduled, Microsoft Security, machine learning, and Fusion. Each type of rule fills a specific niche. Let's explore each of these in turn.
Scheduled
As the name suggests, these rules run on a set schedule to detect suspicious events. For instance, you can have a rule run every few minutes, every hour, every day, or at another time period. The queries for these rules will use KQL to define what they are trying to find. These rules will make up a large proportion of your analytic rules and, if you have used other SIEM systems, are probably the ones you are most familiar with.
Microsoft Security
Microsoft Security rules are used...