Syslog Workbook for Microsoft Sentinel
Introduction
Recently while working on a multiple Syslog Sources, have developed a workbook to show the details of Syslog Data Sources.
Details
Syslog Overview workbook is divided into 2 different areas
2. Queries - Queries to identify various matrices of Syslog Data sources, which are
Design
Have designed the workbook with the combination of Filters & Queries.
Source Code
The Source code for the workbook is available is different places as different option
A. Microsoft Sentinel Workbook Gallery
This workbook is published as a part of Microsoft Sentinel Now
B. Microsoft Sentinel GitHub Code repository
After the pull request validation & approval currently the source code is available in Microsoft Sentinel GitHub repository
C. GitHub Query Store Repository
As a part of ideation & development, all individual queries are documented in the below GitHub repository
Conclusion
This is a descriptive details about the workbook Syslog Overview.
which is developed based on various queries.
Feel free to extend with your thoughts !!!