Microsoft Sentinel Blog

Options
1,765
VipulDabhi on May 23 2024 11:23 AM
1,573
jeffsc on May 13 2024 08:00 AM
6,607
MichalShechter on May 06 2024 09:07 AM
4,254
Israel_Aloni on May 06 2024 08:47 AM
2,633
Eric Burkholder on May 06 2024 06:00 AM
23.9K
robeving on Apr 26 2024 07:51 PM
3,001
Umesh_Nagdev on Apr 19 2024 07:55 AM
2,150
jeffsc on Apr 15 2024 11:17 AM
2,157
jeffsc on Apr 15 2024 11:17 AM
5,248
Preeti_Krishna on Mar 28 2024 02:56 PM
6,352
Matt_Lowe on Mar 14 2024 05:21 PM
4,368
Umesh_Nagdev on Feb 20 2024 07:04 AM
3,489
Josefa-Sepulveda on Feb 08 2024 07:58 AM
5,877
BenjiSec on Feb 06 2024 04:03 AM
5,556
PrateekTaneja on Feb 04 2024 10:22 PM
6,031
madesous on Jan 17 2024 05:27 AM
3,603
GBushey on Jan 16 2024 07:20 AM
4,112
VipulDabhi on Jan 08 2024 11:11 AM
6,822
timurengin on Jan 08 2024 11:10 AM
27.5K
Josefa-Sepulveda on Jan 02 2024 02:24 AM
51.6K
Arjun_Trivedi on Nov 29 2023 10:13 PM
10.5K
skochavi on Nov 27 2023 01:21 PM
9,050
ShaharAviv on Nov 20 2023 10:27 PM
6,961
Eric Burkholder on Nov 15 2023 02:26 PM
64.8K
Erez Einav on Nov 15 2023 08:00 AM
5,872
mahmoudmsft on Nov 08 2023 10:02 AM

Latest Comments

Two years passed since the article is published and would be a great help if it still works.
0 Likes
@mikhailf , making the output the same schema will make it easier to use the same queries across both. I've made a simple PowerShell function for this exact scenario to duplicate tables from an existing one found here. The-Cloud-Brain-Dump/Toolshed/Sentinel Toolbox/Copy-LogAnalyticsTable.ps1 at main...
0 Likes
@Erik_Snijder for data value optimizations - yes! If your custom logs aren't used for detections, or not used at all, it'll be surfaced in a recommendation.
0 Likes
Hi, Does the SOC optimization tool support custom logs at this time?Regards, Erik
0 Likes
Grate article. Thank you. If we want to split logs from Syslog table to another Custom-Table1. Should the Custom-Table1 have the same schema as Syslog?Is it possible to split logs from Syslog to 2 or more tables?
0 Likes