Microsoft Sentinel is Microsoft's cloud-native security information and event management (SIEM) and security orchestration, automation and response (SOAR) solution. It is enabled on top of a Log Analytics workspace, where all collected data is stored and queried with KQL. Sentinel is increasingly managed from the Microsoft Defender portal alongside Defender XDR, though the concepts are the same as in the Azure portal.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.