Analytics rules are how Microsoft Sentinel detects threats. Each rule examines data in the workspace and, when its logic matches, creates alerts, which are grouped into incidents that analysts investigate. Rules can be created from templates in the Content hub solutions or written from scratch.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.