Managing and monitoring Azure Sentinel
Now that you have configured your Azure Sentinel instance and set up some workbooks and playbooks, it is important to manage and monitor Azure Sentinel in order to ensure that you are regularly reviewing and responding to any threats and taking any corrective action that may be required.
Some of the methods available to manage and monitor Azure Sentinel are described as follows.
Azure Sentinel Overview
From the Azure Sentinel | Overview section, you are able to review a selection of alerts and metrics, as shown in the following screenshot:
Here you will be able to review events and alerts, usage, and metrics.
Azure Sentinel Logs
From the Azure Sentinel | Logs section, you may choose from a large number of built-in queries under Log Analytics workspaces and see information on things such as Unauthorized Users and Throttled Users, as shown in the following...