Sentinel POC- Architecture and Recommendations For MSSPs (Part 3)
Migrations
Partners may end up with some gaps, but, not all the rules will have to be converted. Some repositories like unified Microsoft Sentinel and Microsoft 365 Defender repository, also have many artifacts available. Some tools also offers free Sigma rule translations, such as SOC Prime's Uncoder I.O. Also, partners going through the POC may sometimes come up with their own solutions that can be published to the marketplace.
Which Connectors?
There are various data ingestion methods for Microsoft Sentinel. Some of the connectors like syslog and CEF can also support a variety of data sources. It is just a matter of time in figuring out the right method of ingesting a data source. There is also a Zero Trust solution in Content hub having some recommended data connectors, and it sorts them from Foundational, to Basic, to Intermediate, to Advanced.
Considerations:
- Free data- Some data is always free.
- Microsoft Sentinel benefit for Microsoft 365 E5, A5, F5, and G5 customers- Customers currently paying for those licenses can receive "a data grant of up to 5MB per user/day to ingest Microsoft 365 data."
- Ingestion time transformation- Many tables support ingestion time transformation as another way to reduce cost. Partners can use ingestion time transformations to filter out data that is not useful for security analysis. There is also a library of transformations available and these transformations can also be used to mask data.
- Commitment tiers- Previously known as Capacity Reservations, is another way to reduce costs, as much as 65% compared to pay-as-you-go.
Comments
Post a Comment