跳至主要内容

2 篇文章 含有標籤「Microsoft Sentinel」

檢視所有標籤

Qiita 新文章:運用 ASIM Authentication 設計 Sentinel 使用者行為分析

· 閱讀時間約 1 分鐘
James Yip
Managing Director

Eventus 在 Qiita 發布了一篇新的技術文章,介紹如何「擺脫原始資料表依賴,以 ASIM Authentication 作為分析母體,設計 Sentinel 使用者行為分析」。

文章說明,直接依賴 SigninLogs、SecurityEvent 或連接器專屬記錄表來設計分析邏輯,當驗證來源增加時會變得難以維護。文章也探討原始事件量可能碰到查詢結果上限,以及連接器故障或資料延遲造成記錄缺漏的問題。

SIEM+ Now Officially Supports Microsoft Sentinel

· 閱讀時間約 3 分鐘
James Yip
Managing Director

We're announcing that SIEM+ now has full, native support for Microsoft Sentinel, joining our existing integrations with Devo, Splunk, and QRadar. If your organization runs Sentinel as its SIEM, you can now add SIEM+'s alert consolidation and AI-powered triage on top of it without changing anything about your existing Sentinel deployment.