Managing security operations with Azure Sentinel
Azure Sentinel is a scalable, SIEM, and SOAR solution that's hosted on the Azure platform. What do we mean by this? Let's review what SIEM and SOAR are.
SIEM stands for Security Information Event Management. It works by collecting log and event data generated from multiple sources, collating the data on a centralized platform, and performing automated analysis of that data to detect threats. This is not a full description of what a SIEM is but a short review. Many SIEMs, including Azure Sentinel, have capabilities beyond these.
SOAR stands for Security Orchestration, Automation, and Response. SOAR allows companies to collect threat-related data from a range of sources and automate responses to those threats:
Looking at the descriptions, it makes sense for these solutions to work together. SIEM collects logs and events from data sources and detects threats...