Sentinel in Side-by-Side with 3rd Party SIEM using Private Endpoints

Описание к видео Sentinel in Side-by-Side with 3rd Party SIEM using Private Endpoints

In this video, I show one of the possible configurations for having Sentinel work side-by-side with a third-party SIEM. The video contains a full demo of an incident sent to Splunk as a JSON representation including all the details of its alerts and related entities. The configuration includes a Logic App that connects to its backend Storage Account and Event Hub using only private connections. The video shows all the details of this configuration.
Please refer to this article for the details of the implementation:   / video-integrating-sentinel-third-party-sie...  

00:00 Intro
00:48 Demo: sending an Incident from Sentinel to Splunk
03:58 How to create the Logic App with Standard plan
05:10 Logic App design, Connections and Managed Identity
12:52 Networking configuration on the Logic App and its back-end Storage Account
22:32 Networking configuration and IAM role assignment on the Event Hub Namespace
25:34 Diagnostic settings configuration on the Event Hub Namespace
26:43 Configuration of the integration on Splunk
28:13 Conclusion

Комментарии

Информация по комментариям в разработке