Azure Sentinel Reference - Azure Sentinel

Overview

Azure Sentinel is a service that helps you monitor and protect your cloud workloads.

It provides comprehensive threat detection, security analysis, and compliance monitoring. Key features include automated threat detection, threat intelligence, and Azure security policy enforcement.

Key Concepts

Sentinel Hub: The core of Azure Sentinel, where data is ingested, analyzed, and correlates.

Data Sources: Can include Azure Monitor, Azure Security Center, and more.

Threat Detection: Detects threats within your cloud environment.

Azure Functions

Azure Functions are a cloud-native service that allows you to run code in response to events. Sentinel integrates well with Azure Functions.

Use Sentinel to monitor and automate your Azure Functions and manage them.

Azure Kubernetes Service

Azure Kubernetes Service (AKS) is a platform for deploying, managing, and scaling containerized applications.

Sentinel provides insights into AKS clusters for threat detection and security compliance.

Security Policy Enforcement

Sentinel helps you enforce your security policies across your entire cloud environment.

Automated policy enforcement ensures that your Azure resources meet your compliance requirements.

Azure Sentinel Dashboard

A visual dashboard that gives insights into all the key elements of Azure Sentinel.

You can navigate to a specific state of your workloads using this dashboard.