Skip to content

Commit

Permalink
Update Lab_27_MicrosoftSentinelKustoQueries.md
Browse files Browse the repository at this point in the history
  • Loading branch information
R-C-Stewart authored Mar 25, 2024
1 parent 6868524 commit 15ec4fc
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions Instructions/Labs/Lab_27_MicrosoftSentinelKustoQueries.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ lab:

## Lab scenario

Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR solution. Through connecting data sources from Microsoft and third-party security solutions, you have the ability to execute security operations tasks. In this lab exercise, you will create a Microsoft Sentinel workspace with data connectors to Azure AD for executing hunting queries using Kusto Query Language (KQL).
Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR solution. Through connecting data sources from Microsoft and third-party security solutions, you have the ability to execute security operations tasks. In this lab exercise, you will create a Microsoft Sentinel workspace with data connectors to Microsoft Entra ID for executing hunting queries using Kusto Query Language (KQL).

#### Estimated time: 30 minutes

Expand Down Expand Up @@ -39,7 +39,7 @@ Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR solution. Through

1. If prompted, select **OK** to activate the Microsoft Sentinel free trial.

#### Task 2 - Add Azure AD as a Data source
#### Task 2 - Add Microsoft Entra ID as a Data source
**Note** - As of 2/8/2024, the data source is now Microsoft Entra ID.

1. In **Microsoft Sentinel**, navigate on the menu to **Content management** and select **Content hub**.
Expand Down

0 comments on commit 15ec4fc

Please sign in to comment.