Operational tasks for SOC engineers
In this section, we will provide an initial list of tasks that have been identified as engineering tasks. You can use this list as a starting point and then add your own tasks based on what works for your specific requirements. Each component that is added to the SOC architecture will have its own task requirements—for example, if you integrate a cloud access security broker (CASB) solution, you will need to carry out similar tasks within that platform to ensure it is well maintained and sending the appropriate information to Microsoft Sentinel.
Daily tasks
A list of daily tasks for SOC engineers is as follows:
- Monitor the data connectors for two key performance indicators:
A. Ensure the data ingestion is consistent with the expected volume; if the volume drops below the average daily rate it could be caused by a configuration error on the source, preventing the data from being sent to Microsoft Sentinel. This should be investigated...