skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
microsoftdocs/agent-skills170 installs

azure-sentinel

Expert knowledge for Azure Sentinel development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring data connectors, KQL analytics rules, Logic Apps playbooks, data lake jobs, or SAP integration, and other Azure Sentinel related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure Monitor (use azure-monitor), Azure External Attack Surface Management (use azure-external-attack-surface-management).

How do I install this agent skill?

npx skills add https://github.com/microsoftdocs/agent-skills --skill azure-sentinel
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill provides a comprehensive directory of links to official Azure Sentinel documentation. It is designed to help agents fetch up-to-date technical information from Microsoft's trusted documentation site. No security risks were identified.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

  • ZeroLeakspass

    Score: 93/100 · 2 sections analyzed

What does this agent skill do?

Azure Sentinel Skill

This skill provides expert guidance for Azure Sentinel. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L50Diagnosing and fixing Microsoft Sentinel ingestion, connector, KQL, notebook, MCP, SAP, and analytics rule errors, plus monitoring and troubleshooting scheduled rule execution.
Best PracticesL51-L74Best practices for designing, tuning, and operating Microsoft Sentinel: automation, playbooks, KQL hunting, analytics rules, UEBA, ASIM, watchlists, SOC metrics, and solution quality.
Decision MakingL75-L117Guidance for planning Sentinel deployments, costs, data tiers, and connectors, plus detailed strategies to migrate from legacy SIEMs (Splunk, QRadar, ArcSight) and optimize detections and automation.
Architecture & Design PatternsL118-L129Designing Microsoft Sentinel architectures: workspace/tenant layouts, SIEM patterns, BCDR/resiliency, data lake/graph designs, and coexisting with or migrating from other SIEMs.
Limits & QuotasL130-L142Limits, quotas, pricing, and availability of Sentinel features (rules, data lake, MCP), plus constraints and safe management of search jobs and watchlists, and removal implications.
SecurityL143-L162Configuring secure access, permissions, encryption, and RBAC for Microsoft Sentinel, including playbooks, data lake, storage connectors, SAP integration, and automated attack disruption across clouds.
ConfigurationL163-L296Configuring Microsoft Sentinel: data connectors and ASIM schemas, analytics rules, automation/playbooks, TI and SAP integrations, data lake jobs, health/auditing, and solution/workbook setup.
Integrations & Coding PatternsL297-L342Patterns and APIs for integrating Sentinel with logs, threat intel, MCP/AI tools, Logic Apps playbooks, data lake, connectors, and external platforms like AWS, Entra ID, Purview.
DeploymentL343-L357Deploying and customizing Sentinel solutions and content (rules, automation, notebooks, SAP, Copilot agents) via CI/CD, ARM, data lake, and multi-cloud/Stack Hub onboarding.

Troubleshooting

TopicURL
Troubleshoot AWS S3 log ingestion connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/aws-s3-troubleshoot
Troubleshoot Microsoft Sentinel Azure Storage Blob connector issueshttps://learn.microsoft.com/en-us/azure/sentinel/azure-storage-blob-connector-troubleshoot
Troubleshoot Syslog and CEF AMA connectors in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-troubleshooting
Troubleshoot KQL queries and jobs in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-troubleshoot
Resolve common Jupyter notebook errors in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebooks-troubleshooting
Best practices and troubleshooting for Sentinel MCP toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/troubleshoot-sentinel-mcp
Troubleshoot Microsoft Sentinel solution issueshttps://learn.microsoft.com/en-us/azure/sentinel/isv/troubleshoot-sentinel-solutions
Monitor and troubleshoot Sentinel scheduled analytics rule executionhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-optimize-analytics-rule-execution
Troubleshoot Sentinel agentless SAP data connector issueshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-deploy-troubleshoot
Troubleshoot Microsoft Sentinel analytics rule issueshttps://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules

Best Practices

TopicURL
Design Microsoft Sentinel automation rules for SOARhttps://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules
Apply recommended Microsoft Sentinel playbook templates and use caseshttps://learn.microsoft.com/en-us/azure/sentinel/automation/playbook-recommendations
Apply best practices for Microsoft Sentinel workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/best-practices
Apply Sentinel-specific best practices for data collectionhttps://learn.microsoft.com/en-us/azure/sentinel/best-practices-data
Bring custom machine learning models into Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/bring-your-own-ml
Apply sample KQL queries for Sentinel threat huntinghttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-sample-queries
Fine-tune Microsoft Sentinel analytics rule detectionshttps://learn.microsoft.com/en-us/azure/sentinel/detection-tuning
Resolve false positives in Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/false-positives
Handle ingestion delay in Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/ingestion-delay
Use UEBA data to investigate Sentinel incidentshttps://learn.microsoft.com/en-us/azure/sentinel/investigate-with-ueba
Develop and deploy ASIM parsers for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/normalization-develop-parsers
Apply quality guidelines to Sentinel platform solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/platform-solution-quality-guidance
Apply quality guidelines to Sentinel SIEM solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-siem-solution-quality-guidance
Use Sentinel incident metrics to manage SOC performancehttps://learn.microsoft.com/en-us/azure/sentinel/manage-soc-with-incident-metrics
Apply operational best practices for Microsoft Sentinel SOCshttps://learn.microsoft.com/en-us/azure/sentinel/ops-guide
Manage deprecated Microsoft Sentinel solutions lifecyclehttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution-deprecation
Use customizable anomaly detection to find threatshttps://learn.microsoft.com/en-us/azure/sentinel/soc-ml-anomalies
Apply SOC optimization recommendations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-access
Apply Microsoft Sentinel watchlists effectivelyhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists
Manage incident tasks in Sentinel investigationshttps://learn.microsoft.com/en-us/azure/sentinel/work-with-tasks

Decision Making

TopicURL
Plan and execute Sentinel migration from MMA to AMAhttps://learn.microsoft.com/en-us/azure/sentinel/ama-migrate
Decide and migrate Sentinel alert-trigger playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/migrate-playbooks-to-automation-rules
Decide when to use the Microsoft Sentinel data lake tierhttps://learn.microsoft.com/en-us/azure/sentinel/basic-logs-use-cases
Plan and estimate Microsoft Sentinel billing costshttps://learn.microsoft.com/en-us/azure/sentinel/billing
Analyze and optimize Microsoft Sentinel costshttps://learn.microsoft.com/en-us/azure/sentinel/billing-monitor-costs
Choose and optimize Sentinel pre-purchase cost planshttps://learn.microsoft.com/en-us/azure/sentinel/billing-pre-purchase-plan
Reduce and optimize Microsoft Sentinel costshttps://learn.microsoft.com/en-us/azure/sentinel/billing-reduce-costs
Choose and configure Cisco Secure Firewall connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/cisco-ftd-firewall
Choose between Sentinel analytics rules and Defender custom detectionshttps://learn.microsoft.com/en-us/azure/sentinel/compare-analytics-rules-custom-detections
Assess Sentinel connector support across cloudshttps://learn.microsoft.com/en-us/azure/sentinel/data-type-cloud-support
Choose between KQL jobs, summary rules, and search jobs in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs-summary-rules-search-jobs
Choose which logs to ingest into Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-log-ingestion-guidance
Choose detection lifecycle management options in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/detection-lifecycle-management-recommendations
Enroll workspaces in Sentinel simplified pricing tiershttps://learn.microsoft.com/en-us/azure/sentinel/enroll-simplified-pricing-tier
Plan Microsoft Sentinel deployment for data residencyhttps://learn.microsoft.com/en-us/azure/sentinel/geographical-availability-data-residency
Choose Sentinel platform components for ISV solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/which-platform-components-to-build
Choose Microsoft Sentinel log retention tiershttps://learn.microsoft.com/en-us/azure/sentinel/log-plans
Plan Sentinel data tiers and retention strategyhttps://learn.microsoft.com/en-us/azure/sentinel/manage-data-overview
Determine Defender XDR data type support across GCC clouds in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-cloud-support
Decide how to integrate Microsoft Defender XDR with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration
Plan Microsoft Sentinel use in Microsoft Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-sentinel-defender-portal
Plan migration from legacy SIEM to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration
Migrate ArcSight SOAR automation to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-automation
Plan migration of ArcSight rules to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-detection-rules
Export ArcSight historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-historical-data
Convert legacy SIEM dashboards to Sentinel workbookshttps://learn.microsoft.com/en-us/azure/sentinel/migration-convert-dashboards
Ingest exported SIEM data into Sentinel target platformshttps://learn.microsoft.com/en-us/azure/sentinel/migration-export-ingest
Choose target platform for Sentinel historical datahttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-target-platform
Select data ingestion tools for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-tool
Migrate QRadar SOAR automation to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-automation
Plan migration of QRadar rules to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-detection-rules
Export QRadar historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-historical-data
Migrate Splunk SOAR automation to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-automation
Migrate Splunk detection rules to Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-detection-rules
Export Splunk historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-historical-data
Prioritize Microsoft Sentinel data connectors strategicallyhttps://learn.microsoft.com/en-us/azure/sentinel/prioritize-data-connectors
Migrate from Sentinel SAP agent to agentless connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-agent-migrate
Use SIEM migration tool for Sentinel detectionshttps://learn.microsoft.com/en-us/azure/sentinel/siem-migration
Use Sentinel SOC optimization reference recommendationshttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-reference

Architecture & Design Patterns

TopicURL
Design Sentinel BCDR and cross-region resiliencyhttps://learn.microsoft.com/en-us/azure/sentinel/business-continuity-disaster-recovery
Design custom security graphs with Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/custom-graphs-overview
Deploy Sentinel alongside an existing SIEMhttps://learn.microsoft.com/en-us/azure/sentinel/deploy-side-by-side
Design Sentinel across multiple workspaces and tenantshttps://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
Design Sentinel SIEM solution components and patternshttps://learn.microsoft.com/en-us/azure/sentinel/isv/siem-components-to-include
Plan multi-workspace and multi-tenant Sentinel layoutshttps://learn.microsoft.com/en-us/azure/sentinel/prepare-multiple-workspaces
Choose Microsoft Sentinel workspace designs by scenariohttps://learn.microsoft.com/en-us/azure/sentinel/sample-workspace-designs
Configure multi-workspace and tenant architecture in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/use-multiple-workspaces

Limits & Quotas

TopicURL
Configure and understand Sentinel near-real-time ruleshttps://learn.microsoft.com/en-us/azure/sentinel/create-nrt-rules
Microsoft Sentinel data lake service limits referencehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-service-limits
Microsoft Sentinel MCP pricing and usage limitshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-billing
Understand ASIM known issues and limitations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-known-issues
Understand implications of removing Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/offboard-implications
Use Sentinel search jobs for large data setshttps://learn.microsoft.com/en-us/azure/sentinel/search-jobs
Review Microsoft Sentinel service limits and quotashttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-service-limits
Create and upload watchlists in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-create
Manage and update Sentinel watchlists safelyhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-manage

Security

TopicURL
Configure Sentinel playbook authentication and permissionshttps://learn.microsoft.com/en-us/azure/sentinel/automation/authenticate-playbooks-to-sentinel
Restrict access to Sentinel Standard playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/define-playbook-access-restrictions
Enable automated attack disruption actions on AWShttps://learn.microsoft.com/en-us/azure/sentinel/aws-disruption
Configure customer-managed keys for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/customer-managed-keys
Audit Sentinel data lake and graph activities in Purviewhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/auditing-lake-activities
Meet prerequisites to onboard Sentinel data lake and graphhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboarding
Use Sentinel MCP tools in Azure AI Foundryhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-azure-ai-foundry
Connect Sentinel MCP tools in Copilot Studiohttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-copilot-studio
Secure Sentinel Azure Storage blob connectors with NSPhttps://learn.microsoft.com/en-us/azure/sentinel/enable-storage-network-security
Protect MSSP intellectual property in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/mssp-protect-intellectual-property
Configure resource-context RBAC for Sentinel data accesshttps://learn.microsoft.com/en-us/azure/sentinel/resource-context-rbac
Configure Microsoft Sentinel roles and permissionshttps://learn.microsoft.com/en-us/azure/sentinel/roles
Prepare SAP security settings for Sentinel connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/preparing-sap
Assign required ABAP authorizations for Sentinel SAP userhttps://learn.microsoft.com/en-us/azure/sentinel/sap/required-abap-authorizations
Use Sentinel built-in SAP security contenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-security-content
Monitor SAP security parameters for suspicious changeshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-suspicious-configuration-security-parameters

Configuration

TopicURL
Add incident entities as threat indicators in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/add-entity-to-threat-intelligence
Use Sentinel ML anomaly types for detectionhttps://learn.microsoft.com/en-us/azure/sentinel/anomalies-reference
Create Data Collection Rules for Sentinel using API exampleshttps://learn.microsoft.com/en-us/azure/sentinel/api-dcr-reference
Audit Microsoft Sentinel queries and workspace activitieshttps://learn.microsoft.com/en-us/azure/sentinel/audit-sentinel-data
Use SentinelAudit tables for user activity auditinghttps://learn.microsoft.com/en-us/azure/sentinel/audit-table-reference
Configure Microsoft Sentinel automation rule properties and conditionshttps://learn.microsoft.com/en-us/azure/sentinel/automation-rule-reference
Configure Sentinel playbooks for automated threat responsehttps://learn.microsoft.com/en-us/azure/sentinel/automation/automate-responses-with-playbooks
Deploy Business Apps Sentinel solution for Power Platformhttps://learn.microsoft.com/en-us/azure/sentinel/business-applications/deploy-power-platform-solution
Map CEF keys to Microsoft Sentinel CommonSecurityLog fieldshttps://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping
Understand Syslog and CEF AMA connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-overview
Configure Sentinel Security Events for anomalous RDP detectionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-connector-login-detection
Configure ingestion-time data transformation in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/configure-data-transformation
Configure Fusion multistage attack detection rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules
Connect AWS service logs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws
Ingest AWS EKS audit logs from S3 into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-eks
Ingest AWS WAF logs from S3 into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-s3-waf
Connect Azure Virtual Desktop telemetry to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-virtual-desktop
Configure Sentinel connectors for Azure and Microsoft serviceshttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-windows-microsoft-services
Configure syslog and CEF ingestion via AMA to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog-ama
Collect custom text logs via AMA into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs-ama
Ingest Microsoft Defender for Cloud alerts into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-defender-for-cloud
Stream Windows DNS logs to Sentinel with AMAhttps://learn.microsoft.com/en-us/azure/sentinel/connect-dns-ama
Ingest Google Cloud Platform logs into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-google-cloud-platform
Configure Logstash output with Sentinel DCR-based APIhttps://learn.microsoft.com/en-us/azure/sentinel/connect-logstash-data-connection-rules
Enable Defender Threat Intelligence data connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-mdti-data-connector
Stream Microsoft Defender XDR data into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender
Stream Purview Information Protection data to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-purview
Configure API-based Microsoft Sentinel data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-api-based
Configure diagnostic settings-based Sentinel connectionshttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-diagnostic-setting-based
Configure Windows agent-based Sentinel data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-windows-based
Configure scheduled analytics rules from templates in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rule-from-template
Configure custom scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rules
Configure Sentinel incident creation from connected alertshttps://learn.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts
Customize Microsoft Sentinel alert properties from querieshttps://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details
Customize entity timeline activities in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/customize-entity-activities
Configure Azure Storage Blob CCF data connector ruleshttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-azure-storage
Configure GCP Codeless Connector Framework data connection ruleshttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-gcp
Configure RestApiPoller data connector and rules JSONhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-connection-rules-reference
Define Codeless Connector Framework data connector UI JSONhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-ui-definitions-reference
Configure custom data ingestion and transformation for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/data-transformation
Use asset data table mappings in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/asset-data-tables
Create and manage custom graphs in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-custom-graphs
Build deep-link URLs for Sentinel graph querieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-deep-links-graph-queries
Configure federated data connectors in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/data-federation-setup
Create and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Configure and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Configure and run KQL queries in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries
Configure and schedule Sentinel notebook jobs in VS Codehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-jobs
Configure Sentinel data lake connectors and retentionhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-connectors
Create and configure custom Sentinel MCP tools from KQLhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-create-custom-tool
Configure Microsoft Sentinel MCP server for AI querieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started
Use DNS AMA connector fields and normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/dns-ama-fields
Deploy Sentinel Business Apps solution for D365 Financehttps://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/deploy-dynamics-365-finance-operations-solution
Enable auditing and health monitoring for Sentinel resourceshttps://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring
Reference Microsoft Sentinel entity types and identifiershttps://learn.microsoft.com/en-us/azure/sentinel/entities-reference
Review Fusion-detected multistage attack scenarios in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/fusion-scenario-reference
Configure and interpret Sentinel auditing and health monitoringhttps://learn.microsoft.com/en-us/azure/sentinel/health-audit
Use SentinelHealth table for SIEM health monitoringhttps://learn.microsoft.com/en-us/azure/sentinel/health-table-reference
Bulk import threat intelligence indicators into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/indicators-bulk-file-import
Configure push-based codeless connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/create-push-codeless-connector
Build and publish Sentinel custom graph solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/develop-custom-graph-platform-solutions
Develop Jupyter notebook analytics for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/develop-notebook-platform-solutions
Ingest sample telemetry into Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/isv/ingest-sample-data
Configure analytics rules for Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-analytic-rules-creation
Onboard tenants to the Microsoft Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-data-lake-onboarding
Author hunting queries for Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-hunting-rules-creation
Define and publish Sentinel parsers as Kusto functionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-parsers-creation
Create and configure Sentinel summary ruleshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-summary-rules-creation
Build and configure Sentinel workbooks for solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-workbook-creation
Manage template versions for Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/manage-analytics-rule-templates
Configure Sentinel table tiers and retention settingshttps://learn.microsoft.com/en-us/azure/sentinel/manage-table-tiers-retention
Configure entity mappings in Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities
Use Microsoft Purview Information Protection audit record types in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-purview-record-types-activities
Configure Defender alert grouping to match Sentinel incidentshttps://learn.microsoft.com/en-us/azure/sentinel/migrate-sentinel-incident-creation-rules-alert-grouping
View and manage MITRE ATT&CK coverage in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/mitre-coverage
Audit and monitor Sentinel analytics rule healthhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-analytics-rule-integrity
Monitor Sentinel automation rules and playbook healthhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-automation-health
Monitor Sentinel data connector health with workbookshttps://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health
Monitor SAP connector health and performance in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-sap-system-health
Onboard and manage multiple Sentinel tenants via Lighthousehttps://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers
Configure multi-workspace incident views in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/multiple-workspace-view
Configure near-real-time analytics rules for fast detectionhttps://learn.microsoft.com/en-us/azure/sentinel/near-real-time-rules
Manage workspace-deployed ASIM parsers in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-about-workspace-parsers
Use ASIM common schema fields in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-common-fields
Implement ASIM Application Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-application
Implement ASIM Device Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-device
Implement ASIM User Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-user
Convert Sentinel analytics rules to ASIM schemashttps://learn.microsoft.com/en-us/azure/sentinel/normalization-modify-content
Map AI agent telemetry to ASIM Agent schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-agent
Normalize security alerts with ASIM Alert schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-alert
Use ASIM Asset Entity schema in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-asset
Map audit trail logs to ASIM Audit schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-audit
Normalize authentication logs with ASIM schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-authentication
Map DHCP server events to ASIM DHCP schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dhcp
Normalize DNS logs using ASIM DNS schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dns
Map file activity logs to ASIM File Event schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-file-event
Normalize network sessions with ASIM Network schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-network
Map process activity to ASIM Process Event schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-process-event
Normalize Windows registry events with ASIM schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-registry-event
Map user management activity to ASIM schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-user-management
Use legacy Microsoft Sentinel network normalization schema v0.1https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-v1
Normalize web traffic with ASIM Web Session schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-web
Configure Microsoft Sentinel Jupyter notebooks with MSTICPyhttps://learn.microsoft.com/en-us/azure/sentinel/notebook-get-started
Configure MSTICPy and Jupyter notebooks for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/notebooks-msticpy-advanced
Restore and manage archived Sentinel log datahttps://learn.microsoft.com/en-us/azure/sentinel/restore
Configure SAP HANA audit log collection in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/collect-sap-hana-audit-logs
Configure agentless SAP data connector for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-data-connector-agentless
Configure SAP security content and detections in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deployment-solution-configuration
Use SAP Sentinel workspace functions for security analysishttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-function-reference
Reference SAP Sentinel logs, tables, and schemashttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-log-reference
Stop SAP data collection with Sentinel agentless connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/stop-collection
Configure SAP connector polling and DCR in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/update-sap-connector-data-collection-rule
Configure scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/scheduled-rules-overview
Use Microsoft Sentinel security alert schema fieldshttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema
Configure Sentinel alert schemas for XDR connectorshttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema-differences
Understand Sentinel out-of-the-box content centralizationhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-content-centralize
Configure Sentinel Zero Trust (TIC 3.0) monitoring solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution
Set up Azure Storage Blob connector for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/setup-azure-storage-connector
Configure and use Sentinel summary ruleshttps://learn.microsoft.com/en-us/azure/sentinel/summary-rules
Configure custom details in Microsoft Sentinel alertshttps://learn.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts
Configure threat intelligence feed integrations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/threat-intelligence-integration
Configure filter and split data transformations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/transformation-filter-split
Reference UEBA entity enrichments and data sourceshttps://learn.microsoft.com/en-us/azure/sentinel/ueba-reference
Configure Custom Logs via AMA for specific applicationshttps://learn.microsoft.com/en-us/azure/sentinel/unified-connector-custom-device
Enable matching analytics with Microsoft threat intelligencehttps://learn.microsoft.com/en-us/azure/sentinel/use-matching-analytics-to-detect-threats
Use Microsoft Sentinel built-in watchlist schemashttps://learn.microsoft.com/en-us/azure/sentinel/watchlist-schemas
Use watchlists in KQL queries and detection ruleshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-queries
Select Windows security event sets for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/windows-security-event-id-reference
Query STIX objects and migrate to new TI tables in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-stix-objects-indicators
Provision and operate Sentinel workspace manager at scalehttps://learn.microsoft.com/en-us/azure/sentinel/workspace-manager

Integrations & Coding Patterns

TopicURL
Use automation integrations in Microsoft Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/integrations
Leverage Azure Logic Apps workflows for Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/logic-apps-playbooks
Use Microsoft Sentinel playbook triggers and actions via Logic Appshttps://learn.microsoft.com/en-us/azure/sentinel/automation/playbook-triggers-actions
Configure AWS environment to send logs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-configure-environment
Connect Microsoft Entra ID logs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory
Integrate Microsoft Sentinel with data sources using Azure Functionshttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-functions-template
Integrate STIX/TAXII threat feeds and exports with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii
Connect threat intelligence platforms to Sentinel (legacy connector)https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-tip
Integrate TIP feeds with Sentinel via upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api
Author custom graphs with AI in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-graphs-with-ai
Query Sentinel graphs using GQL syntax and operatorshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/gql-reference-for-sentinel-custom-graph
Call Sentinel custom graph REST APIs from clientshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/graph-rest-api
Query and visualize custom graphs in Sentinel graphhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/graph-visualization
Use REST APIs to run KQL on Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api
Query Sentinel data lake from Jupyter notebookshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-examples
Use the Sentinel graph provider APIhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-graph-provider-reference
Use Sentinel MCP agent creation toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-agent-creation-tool
Enable Sentinel MCP connector in ChatGPT or Claudehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-chatgpt-claude-connector
Use Sentinel MCP data exploration toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-data-exploration-tool
Build Logic Apps with Sentinel MCP entity analyzerhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-logic-apps
Add Sentinel MCP tools to Security Copilothttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-security-copilot
Integrate Sentinel MCP tools with VS Codehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-visual-studio-code
Use MicrosoftSentinelProvider class to access data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-provider-class-reference
Query and use federated data sources in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/using-data-federation
Enrich Sentinel entities with geolocation data using REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/geolocation-data-api
Manage Sentinel hunting queries via Log Analytics REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/hunting-with-rest-api
Integrate Defender for Cloud incidents into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ingest-defender-for-cloud-incidents
Develop Security Copilot agents with Sentinel datahttps://learn.microsoft.com/en-us/azure/sentinel/isv/build-agent-security-copilot
Build pull codeless connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/isv/create-codeless-connector
Build AI-assisted custom Sentinel data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/isv/create-custom-connector-builder-agent
Implement nested API polling in Sentinel connectorshttps://learn.microsoft.com/en-us/azure/sentinel/isv/custom-connector-nested-api-polling
Implement multi-account Sentinel codeless connector patternshttps://learn.microsoft.com/en-us/azure/sentinel/isv/multi-account-ccf-connector
Create Sentinel playbooks for automated responseshttps://learn.microsoft.com/en-us/azure/sentinel/isv/sentinel-playbook-creation
Use ASIM KQL parsers for normalized Sentinel querieshttps://learn.microsoft.com/en-us/azure/sentinel/normalization-about-parsers
Apply ASIM helper functions in KQL querieshttps://learn.microsoft.com/en-us/azure/sentinel/normalization-functions
Integrate Microsoft Purview insights with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/purview-solution
Trigger Sentinel playbooks from investigation entitieshttps://learn.microsoft.com/en-us/azure/sentinel/respond-threats-during-investigation
Call Sentinel SOC optimization recommendations APIhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-api
Import threat intelligence STIX objects into Sentinel via upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/stix-objects-api
Extract non-native incident entities with Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/tutorial-extract-incident-entities
Configure Syslog via AMA for specific applianceshttps://learn.microsoft.com/en-us/azure/sentinel/unified-connector-syslog-device
Use legacy Sentinel upload indicators API for STIX IOCshttps://learn.microsoft.com/en-us/azure/sentinel/upload-indicators-api

Deployment

TopicURL
Set up CI/CD deployments of custom Sentinel contenthttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd
Customize repository-based content deployments in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-deploy
Onboard Azure Stack Hub virtual machines to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-stack
Deploy Sentinel data lake from Microsoft Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboard-defender
Check Microsoft Sentinel feature availability by cloudhttps://learn.microsoft.com/en-us/azure/sentinel/feature-availability
Deploy Sentinel analytics rules via ARM templateshttps://learn.microsoft.com/en-us/azure/sentinel/import-export-analytics-rules
Deploy Sentinel automation rules via ARM templateshttps://learn.microsoft.com/en-us/azure/sentinel/import-export-automation-rules
Package and deploy Sentinel graph/notebook solutionshttps://learn.microsoft.com/en-us/azure/sentinel/isv/package-publish-notebook-graph-solutions
Publish Microsoft Security Copilot agents to storehttps://learn.microsoft.com/en-us/azure/sentinel/isv/publish-agent-to-security-store
Publish Sentinel SIEM solutions via Partner Centerhttps://learn.microsoft.com/en-us/azure/sentinel/isv/publish-sentinel-solutions
Deploy Microsoft Sentinel solution for SAP BTPhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-sap-btp-solution
Prepare Sentinel SAP agentless connector deploymenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/prerequisites-for-deploying-sap-continuous-threat-monitoring

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/microsoftdocs/agent-skills/azure-sentinel">View azure-sentinel on skillZs</a>