Microsoft Sentinel + Splunk/Elastic concepts

Lesson#95 of 107 in project Theory

Learn

  • log ingestion
  • agents/connectors
  • parsing
  • normalization
  • fields
  • indexes/data sources
  • queries
  • dashboards
  • alerts
  • correlation
  • rules
  • investigations