メインコンテンツまでスキップ

「Microsoft Sentinel」タグの記事が2件件あります

全てのタグを見る

QiitaでSentinelのユーザー行動分析に関する新しい記事を公開しました

· 約2分
James Yip
Managing Director

Eventusは、Qiitaで新しい技術記事を公開しました。タイトルは「生テーブル依存をなくすSentinelユーザー行動分析設計――ASIM Authenticationを母集団にする」です。

この記事では、SigninLogsやSecurityEventなどの生テーブルに直接依存する設計が、認証ソースの増加とともに保守しにくくなる理由を解説しています。イベント数の増加によるクエリ結果の上限や、コネクタの障害・取り込み遅延によるデータ欠損についても取り上げます。

SIEM+ Now Officially Supports Microsoft Sentinel

· 約3分
James Yip
Managing Director

We're announcing that SIEM+ now has full, native support for Microsoft Sentinel, joining our existing integrations with Devo, Splunk, and QRadar. If your organization runs Sentinel as its SIEM, you can now add SIEM+'s alert consolidation and AI-powered triage on top of it without changing anything about your existing Sentinel deployment.