Syslog Workbook for Microsoft Sentinel

Syslog Workbook for Microsoft Sentinel

Introduction

Recently while working on a multiple Syslog Sources, have developed a workbook to show the details of Syslog Data Sources.

Details

Syslog Overview workbook is divided into 2 different areas

  1. Filters - Filters are loaded on the current context of the workbook, which are

  • TimeRange
  • Subscription
  • Workspace
  • HostName
  • Facility
  • SeverityLevel

2. Queries - Queries to identify various matrices of Syslog Data sources, which are

  • Data Ingestion Trend
  • Heartbeat
  • HostNames
  • Facility
  • Severity Level
  • Severity Trend Summary
  • Syslog Trend
  • Timeline

Design

Have designed the workbook with the combination of Filters & Queries.

No alt text provided for this image

Source Code

The Source code for the workbook is available is different places as different option

A. Microsoft Sentinel Workbook Gallery

This workbook is published as a part of Microsoft Sentinel Now

No alt text provided for this image

B. Microsoft Sentinel GitHub Code repository

After the pull request validation & approval currently the source code is available in Microsoft Sentinel GitHub repository

C. GitHub Query Store Repository

As a part of ideation & development, all individual queries are documented in the below GitHub repository

No alt text provided for this image


Conclusion

This is a descriptive details about the workbook Syslog Overview.

which is developed based on various queries.

Feel free to extend with your thoughts !!!

要查看或添加评论,请登录

Samik Roy [MVP]的更多文章

社区洞察

其他会员也浏览了