Azure Sentinel Solution
Last month I had a webinar about “Azure security and consideration, where one of my slides I mentioned about Azure Sentinel solution which I wanted to cover more in depth here in this blogpost. Now the basic thing you need to understand is that Sentinel is a module/solution which runs on top of Log Analytics. Log Analytics as a standalone component is used by a lot of other services in Azure as well, just to give an example. Log Analytics can be used in combination with Azure Monitor, Network Watcher, Azure Automation, Application Insight, Diagnostics Logs, Application logs and so on. Overview of service usage and pricing Microsoft always recommends that you have a few workspaces as possible, why? Well let us say that we have Log Analytics installed on a virtual machine where we want to collect security events from. (At the same time we also want to collect performance me07ics for monitoring purposes. For Windows multihoming is possible, but you cannot...