077 - Sentinel News und Video Konferenzen

Published: Feb. 25, 2022, 3:28 p.m.

b'

Gundog v2: install-module gundog https://emptydc.com/2022/02/08/gundog-2/

\\n

PowerShell um TenantID zu bekommen: https://github.com/jangeisbauer/MiscPowerShell/blob/main/Get-TenantIDbyName.ps1

\\n

Basic Logs (im Kontrast zu Analytic Logs)

\\n
    \\n
  • Gro\\xdfe Datenmenen wie Netzwerklogs
  • \\n
  • G\\xfcnstigere Ingestions Kosten
  • \\n
  • Daf\\xfcr Kosten f\\xfcr Queries
  • \\n
  • Retention 8 Tage (statt 90)
  • \\n
  • Keine Alerts nur f\\xfcr Ad Hoc Hunting
  • \\n
\\n

Archived Logs

\\n
    \\n
  • 7 Jahre
  • \\n
  • Low cost
  • \\n
\\n

IngestionTime Transformations: https://docs.microsoft.com/en-us/azure/azure-monitor/logs/ingestion-time-transformations

'