Welcome back to my Microsoft Sentinel Blogseries! In this episode I will give you some basic examples of how to deploy a Basic Sentinel Instance (trough the Azure Portal) addressing the Sentinel Intance, Data Connectors, Analytics Rules and a Playbook setup! Please make sure to read my previous blog about these subjects first!
Creating a Log Analytics Workspace
data:image/s3,"s3://crabby-images/b1331/b1331cb3ce71e5aeedb62c9409fb292afb7ade27" alt=""
- From the Log Analytics workspaces menu in the Azure portal, select your workspace.
- Select Usage and estimated costs in the left pane.
- Select Data Retention at the top of the page.
- Change retention to a retention you would like to use, for example 365 days.
- After creation make sure you set the Entra ID Diagnostic settings to send all of the logs to this Workspace!
Creating a Sentinel Instance
data:image/s3,"s3://crabby-images/17e5a/17e5a41b15529697297087a7bb4c8a0e7ed7be73" alt=""
- Click “Add”, this takes a while.
- Finally you are presented with Microsoft Sentinel!
data:image/s3,"s3://crabby-images/e295d/e295d70574e7583c77c3e02db4cb8dc6eac90793" alt=""
- Within Sentinel, go to Settings -> Playbook Settings and give Sentinel Access to run Paybooks in your Subscription(s)
data:image/s3,"s3://crabby-images/f04c5/f04c5ab301ddfdc0d5952207f610a1e7ac1cf96c" alt=""
- Now we are ready to get started with Configuring Microsoft Sentinel!
Implementing a Data Connector
Now we have an Sentinel Instance configured we are ready to create our first Data Connector! For this example I’m going to configure Microsoft Entra ID.
- Within Sentinel go to the Content Hub and search for “Micosoft Entra ID”
- Please click “Install” -> Note: you see that there are Analytics Rules, Workbooks and Playbooks in this Solution which we are configuring later!
data:image/s3,"s3://crabby-images/740e7/740e7a46a4d45de28b88d43c36a80ca8a664d0a0" alt=""
data:image/s3,"s3://crabby-images/b69ac/b69ac02d515155c74cd99634847a84b0198bca26" alt=""
data:image/s3,"s3://crabby-images/536e4/536e48105d42134f129d5564e0d7202ade8aaf93" alt=""
data:image/s3,"s3://crabby-images/49d69/49d694d1b7564fa2bb0145cf7e43d1cb0d556085" alt=""
- Your Data Connector is now ready to import Data into Sentinel (this might take up to 24 hours
Implementing a Analytics Rule
In this example we are going to use an Analytics Rule which is associated with the Microsoft Entra ID Data Connector
- Go to the Solution Settings menu as shown in step 4 of the previous Subject.
- Select a rule of your choice and “Create Rule”
data:image/s3,"s3://crabby-images/443a9/443a946b6b02011d608fb6b88dc89b24636afd4b" alt=""
- Now we are in the Rule Settings, you are able to change information and logic of this rule template to match your own requirements.
- On the Incident Settings, configure if your want Sentinel to create Incidents based on this Rule
data:image/s3,"s3://crabby-images/8564c/8564cac2dbe07a28ce1f79e54eb1299b046343ea" alt=""
- On the Automation response tab, you can add actions as you desire. For example running a Playbook when this Alert occurs!
data:image/s3,"s3://crabby-images/c8f56/c8f566ebcf2c4cd4b2de3ef3231de60249b13943" alt=""
- Your rule is now active!
Implementing a Playbook
In this example we are going to use an Playbook which is associated with the Microsoft Entra ID Data Connector
- Go to the Solution Settings menu as shown in step 4 of the previous Subject.
- Select a Playbook and Select Configuration
data:image/s3,"s3://crabby-images/d2d3e/d2d3e15fcd72ee2505b4e94c4130d54f88ebfd7c" alt=""
data:image/s3,"s3://crabby-images/79f28/79f28412d8e8cd3c0c8a037b2c49e49963242bac" alt=""
data:image/s3,"s3://crabby-images/fb417/fb4170dfcd6eb169ea180014f44402c6d8e8c962" alt=""
- Note the Connections that are needed, sometime the Paybooks create Managed Identities which need additional Roles!
data:image/s3,"s3://crabby-images/d61bd/d61bd97c9121e02a7c8f7dc84fcc4ca863507a12" alt=""
data:image/s3,"s3://crabby-images/32044/3204443ee657ec0f14f54e1910ad5a5403deb36f" alt=""
data:image/s3,"s3://crabby-images/d474e/d474ef4e35c590a32a610fbee1c19d7cb4f2b6d0" alt=""
- Now your Playbook is ready to go! Please add as an automation action to Analytics Rules 😊
I hope that with this blog in the Sentinel Series you will be able to setup a Basic Microsoft Sentinel Instance! Please follow my upcoming blogs about more Sentinel Features!