Reviewing Microsoft Sentinel components
Now that we have learned how to enable Microsoft Sentinel in your environment, this recipe will provide you with a high-level overview of its capabilities and components.
As a cloud-based SIEM and SOAR solution, Sentinel can act as the tooling to support a SOC and SOC-as-a-Service approach.
Getting ready
This recipe requires the following:
- A device with a browser, such as Edge or Chrome, to access the Azure portal: https://portal.azure.com
- Access to an Azure subscription, where you have access to the Owner role
- The subscription should have Microsoft Sentinel enabled
How to do it…
This task consists of the following step:
- Review the Microsoft Sentinel components
Task – Microsoft Sentinel
Perform the following steps:
- Sign in to the Azure portal: https://portal.azure.com.
- From the search bar, type
Microsoft Sentinel
; click Microsoft Sentinel from the list of services...