azure-docs icon indicating copy to clipboard operation
azure-docs copied to clipboard

Table creation and table mappings for the Sentinel tables

Open andrePKI opened this issue 3 years ago • 1 comments

This article is about Sentinel data. That is of the same structure and format for all customers. Is there any resource or repository which contains the target table definition and corresponding mapping? We are struggling with the creation of the tables and appropriate table mappings for the tables we have in Sentinel (about 100) and can't believe this hasn't been done before.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

andrePKI avatar Oct 20 '22 16:10 andrePKI

@andrePKI Thanks for your feedback! We will investigate and update as appropriate.

YashikaTyagii avatar Oct 21 '22 03:10 YashikaTyagii

Hi and thanks for your feedback! Tagging a current content owner - @yelevin , can you take a look?

batamig avatar Oct 25 '22 06:10 batamig

@bwren Do you know how to answer this? Thanks.

yelevin avatar Oct 25 '22 09:10 yelevin

#assign:austinmccollum

cwatson-cat avatar Nov 08 '22 16:11 cwatson-cat

@andrePKI There's a table reference in this library: https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/sentinelaudit

You can also run the getschema operator in your workspace to get more info about a table: https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/getschemaoperator

cwatson-cat avatar Nov 08 '22 21:11 cwatson-cat

@andrePKI, happy to hear if this addresses what you're looking for.

rayne-wiselman avatar Feb 19 '23 12:02 rayne-wiselman

The above sure helps, but I also found this article on MS learn which refers to this powershell script I used that as a starting point and tweaked it for completeness. So I am happy now

andrePKI avatar Feb 19 '23 20:02 andrePKI