Azure Sentinel
A cloud-native‘SecurityInformation&Event Manager’(SIEM) tool
withinMicrosoftAzure
It takes 20 years to build a reputation and few minutes
of cyber-incident to ruin it.” – Stephane Nappo
Youcancontactus atinfo@alliedc.com
Cloud-native SIEM
Azure Sentinel
““Advanced AI and security analytics to help you
detect, hunt, prevent, and respond to threats
across your organization.”
Admins need tokeep on-premise& cloudservices secure, separately.
Rapidlygrowingnumberofdevices in thecorporatenetworks
Firewalls/Anti-malwaregeneratealot offalsealarms
There’s a silos b/wincident management & information security
The challenge
Types of attack
AzureSentinel
Cloud native solution
Solution Options
Managed/Unmanaged
SIEM on ElasticSearch
Log term log data retention
Solutioncapabilities
Data aggregation frommultiple sources
including network, security, servers, DBs,
apps, & on-premise/cloud native services
Content itself is what the end-user derives
value fromalso can refer tothe
information provided through the
medium,
Dashboards &alerts
Reporting compliant toexisting security,
governance, &audit processes
Search logs on different
nodes
SIEM on ElasticSearch
SIEM on ElasticSearch
Azure Sentinel (Dashboard)
Built onAzureLog
Analyticsbutaddsa
lotmorepower
AI capabilitiesenable
Sentineltodistinguish
threatsfromglitches
Write yourdescription here
RunsunderAzure
portal
Enableyou towork with
various dataformats &
sources
Integrations
Completeoverview
ofextended
network
Azure Sentinel
False alarms & surfaces genuine
threats
Reduces
Securityanalytics inone cloud
service
Sentinel brings
Necessitates to workwith
multiple tools
Dealing with each system
separately, which is inefficient
The old way
Admins find problems quickly&
reliably
Lets
Doesn’t give the ‘Big Picture’
Stifles visibility
Parting thoughts
Visit usat:www.alliedc.com
Ordropus aline atinfo@alliedc.com
Any questions?
Thanks!

Azure sentinal