You have an Azure subscription that contains a Log Analytics workspace.
You need to onboard Microsoft Sentinel.
What should you do first?
You have an Azure subscription that contains a Log Analytics workspace.
You need to onboard Microsoft Sentinel.
What should you do first?
Before you can use Microsoft Sentinel, the first step is to connect to your data sources. Microsoft Sentinel relies on data from these sources to provide insights and detect threats. Without connecting to data sources, you wouldn't be able to utilize Sentinel's features such as creating hunting queries, correlating alerts, or creating custom detection rules.
Correct. This involves setting up connections between Microsoft Sentinel and your data sources, such as Azure resources, Office 365, or third-party solutions.
Answer: Connect to your data sources
Using a connector to connect to data sources
Duplicate question #168