TY - BOOK AU - Diogenes, Yuri AU - DiCola, Nicholas AU - Turpijn, Tiander TI - Microsoft sentinel: planning and implementing Microsoft's cloud-native SIEM solution SN - 978-0-13-790093-0 AV - QA 76.585 D56 2023 PY - 2023/// CY - [S.l.] PB - Pearson Education, Inc. KW - CLOUD COMPUTUNG SECURITY MEASURES KW - MICROSOFY AZURE (COMPUTER PLATFORM) N1 - Includes index and suggested learning resources; CHAPTER 1: Security challenges for SecOps CHAPTER 2: Introduction to Microsoft Sentinel CHAPTER 3: Analytics CHAPTER 4: Incident management CHAPTER 5: Hunting CHAPTER 6: Notebooks CHAPTER 7: Automating response CHAPTER 8: Data visualization CHAPTER 9: Data connectors APPENDIX A: Introduction to Kusto Query Language APPENDIX B: Microsoft Sentinel for managed security service providers N2 - Build next-generation security operations with Microsoft Sentinel. Microsoft Sentinel is the scalable, cloud-native, security information and event management (SIEM) solution for automating and streamlining threat identification and response across your enterprise. Now, three leading experts guide you step-by-step through planning, deployment, and operations, helping you use Microsoft Sentinel to escape the complexity and scalability challenges of traditional solutions. Fully updated for the latest enhancements, this edition introduces new use cases for investigation, hunting, automation, and orchestration across your enterprise and all your clouds. The authors clearly introduce each service, concisely explain all new concepts, and present proven best practices for maximizing Microsoft Sentinels value throughout security operations ER -