- Learn Azure Sentinel
- Richard Diver Gary Bushey Jason S. Rader
- 207字
- 2021-06-30 15:08:17
Chapter 2: Azure Monitor – Log Analytics
In this chapter, we will explore the Azure Monitor Log Analytics platform, which is used to store all the log data that will be analyzed by Azure Sentinel. This is the first component that needs to be designed and configured when implementing Azure Sentinel, and will require some ongoing maintenance to configure the data storage options and control the costs associated with the solution.
This chapter will also explain how to create a new workspace using the Azure portal, PowerShell, and the CLI. Once a workspace has been created, we will learn how to attach various resources to it so that information can be gathered, and we will explore the other navigation menu options.
By the end of this chapter you will know how to set up a new workspace, connect to resources to gather data, enable Azure Sentinel for data analysis, and configure some of the advanced features to ensure security and cost management.
We will cover the following topics in this chapter:
- Introduction to Azure Monitor Log Analytics
- Planning a workspace
- Creating a workspace
- Managing permissions of the workspace
- Enabling Azure Sentinel
- Exploring the Azure Sentinel Overview page
- Connecting your first data source
- Advanced settings for Log Analytics
- 攻守道:企業數字業務安全風險與防范
- Securing Blockchain Networks like Ethereum and Hyperledger Fabric
- 暗戰亮劍:黑客滲透與防御全程實錄
- INSTANT Metasploit Starter
- Getting Started with FortiGate
- 安全技術運營:方法與實踐
- 黑客攻防與網絡安全從新手到高手(絕招篇)
- Digital Forensics with Kali Linux
- 華為防火墻實戰指南
- 網絡用戶行為的安全可信分析與控制
- 網絡關鍵設備安全檢測實施指南
- 網絡空間安全體系
- 網絡安全攻防技術實戰
- 中國網絡空間安全前沿科技發展報告(2018)
- 網絡空間安全技術