A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
1,458 questions with Microsoft Security | Microsoft Sentinel tags
Defender Unified RBAC also shows “Failed to load workspace data.”
I have a Microsoft Sentinel workspace connected to Defender XDR as Primary, but Advanced Hunting does not show any Sentinel workspace tables in Schema. workspace('<WorkspaceID>').<Table> is unavailable, while Azure Portal Sentinel/Log…
Microsoft Security | Microsoft Sentinel
Unable to create automation rules for Sentinel
Hi experts, I have tried Defender Portal -> Sentinel -> Configuration -> Automation to create a new automation rule to assign new alerts to a user. But it failed with error "You don't have permission to perform this action." User:…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Azure Workbook
Hi i have an issue i am enountering. I am tryingto have different ysplit panels in azure but i cant. I used he render qquery but it is like ignore when running. Here is my query let SHO_CPU = Perf | where Computer in (dynamic([{WVDHosts}])) | where…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Unable to onboard Sentinel workspace from Lighthouse to Defender
I got the following error "Failed to log-lighthouse workspace. Try again later." when I tried to connect a customer's Microsoft Sentinel workspace to Microsoft Defender XDR. This is to migrate Microsoft Sentinel in the Azure portal to the…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel Stuck in a Loop in the Defender Portal
In the microsoft defender portal with sentinel, i have connected, disconnected and waited 30 minutes, and reconnected the SIEM workspace. if i go to sentinel and any of the tabs in defender, it just loops to the connectors page as if the workspace is not…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Cannot onboard Okta Single Sign on logs to Sentinel UEBA
Hi, I am trying to connect Okta to Sentinel UEBA. When I attempt to do this in the Defender XDR portal, I receive an error message saying, 'Data source is not ingested to Sentinel'. The selector to enable the functionality is greyed out. I have: …
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel UEBA data source fails with InternalServerError (HTTP 500)
Hi, I am trying to enable an additional AWS CloudTrail data source under Microsoft Sentinel UEBA in the Microsoft Defender portal. The AWSCloudTrail table is already receiving data normally in Sentinel. I also checked the CloudTrail data and confirmed…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
How to ingest Windows Event Logs from Tenant B's WEC (native Azure VM) to Tenant A?
We've deployed lighthouse on Tenant B to give permission on Tenant A's Admin. We have a DCR that is already there associated with our on prem WEC and that's ingesting logs to WindowsEvent Table. We have successfully associated Tenant B's WEC to our DCR…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Secondary Sentinel workspace not visible in Defender portal
Summary Created a new Sentinel workspace (testspace) in our test subscription. It shows Connected and Active in Microsoft Defender, and I have Owner access to the subscription, resource group, and workspace plus Defender Read & Manage…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Playbooks not listed and "Failed to fetch playbook runs in one or more selected subscriptions" appeared suddenly across multiple tenants
We are an MSSP managing multiple Microsoft Sentinel workspaces across separate customer tenants via Azure Lighthouse. As of today, the Automation / Active playbooks view fails to list playbooks and returns "Failed to fetch playbook runs in one or…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Sentinel workspace tables not appearing in Defender portal advanced hunting schema
Microsoft Sentinel workspace tables are not queryable in the Defender portal advanced hunting page. The Schema tab only shows six Defender XDR tables and no workspace table group appears. Querying AzureActivity returns a semantic error saying it failed…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Microsoft Sentinel – “Failed to fetch playbook runs in one or more selected subscriptions” and Playbook List not showing in Run playbook on incident sentinel area
We are facing an issue while trying to manually execute a Microsoft Sentinel playbook from a Sentinel incident. When we open an incident and select Actions → Run playbook, the playbook pane does not load any available playbooks. Instead, we receive the…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
AI answer
Governance relationships can't co-exist with pre-configured GDAP admin relationship
I operate for an MSSP, we are CSP as well. Below is our setup - We have GDAP setup for our clients to support their 365 services. We have Azure lighthouse to centrally manage their subscriptions. Microsoft announced last year that Sentinel is going…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Clarification on Scheduling Capability for Azure/Microsoft Sentinel Workbooks
Do Azure/Microsoft Sentinel workbooks support native scheduling (auto-refresh or timed execution) and/or scheduled report/export generation? If not, what is the Microsoft-recommended approach (e.g., Logic Apps, KQL jobs, Power BI) to achieve scheduled…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
how can participate for Advanced KQL for SecOps?
how can participate for Advanced KQL for SecOps? Best Regards. Ignacio.
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Validation of public IPs from microsoft
Dear Microsoft Support Team, We are reaching out to inquire about the following IP addresses: 131.107.2.221 131.107.2.131 141.107.2.61 192.167.1.2 Could you please confirm if these IP addresses are part of Microsoft services? We have received…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Functions editing in Sentinel/Log Analytics doesn't work anymore
When I select "load code to editor" to edit a workspace function in Sentinel/LogAnalytics, the code isn't loaded in a new dedicated tab, but in the current one and treated as brand new code, that I can only save as a new function. This way I…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Functions: Legacy Category and Load to Editor Issues
Hello all! I have observed two unsettling behaviours when navigating Microsoft Sentinel through the Portal. I no longer see Legacy Category when trying to select Group By on Functions. Only Solution and Category. I am still able to add a Legacy…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
What could be the problem?
Logs blade in sentinel showing connection to server error. KQL queries can't retrieve data because of said error
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
AI answer
Microsoft Graph Activity Logs (MicrosoftGraphActivityLogs) enabled correctly but table remains empty in Log Analytics/Sentinel
We have Microsoft Graph Activity Logs enabled as a category on our Microsoft Entra ID diagnostic setting, routed to a Log Analytics workspace with Microsoft Sentinel enabled. The category shows as checked/saved in both the Entra ID Diagnostic Settings…
Microsoft Security | Microsoft Sentinel
A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems