|
5 | 5 | items: |
6 | 6 | - name: What is Microsoft Sentinel? |
7 | 7 | href: overview.md |
| 8 | + - name: Microsoft Sentinel data lake overview |
| 9 | + href: datalake/sentinel-lake-overview.md |
| 10 | + displayName: data lake |
8 | 11 | - name: What's new |
9 | 12 | href: whats-new.md |
10 | 13 | - name: Best practices |
11 | 14 | href: best-practices.md |
12 | 15 | - name: Experience in Defender portal |
13 | 16 | href: microsoft-sentinel-defender-portal.md |
| 17 | +- name: Data lake exploration |
| 18 | + items: |
| 19 | + - name: KQL for data lake exploration |
| 20 | + items: |
| 21 | + - name: Overview |
| 22 | + href: datalake/kql-overview.md |
| 23 | + displayName: data lake |
| 24 | + - name: Run KQL queries |
| 25 | + href: datalake/kql-queries.md |
| 26 | + displayName: data lake |
| 27 | + - name: Create KQL jobs |
| 28 | + href: datalake/kql-jobs.md |
| 29 | + displayName: data lake |
| 30 | + - name: Manage KQL jobs |
| 31 | + href: datalake/kql-manage-jobs.md |
| 32 | + displayName: data lake |
| 33 | + - name: Troubleshoot KQL for the lake |
| 34 | + href: datalake/kql-troubleshoot.md |
| 35 | + displayName: data lake |
| 36 | + - name: Notebooks for data lake exploration |
| 37 | + items: |
| 38 | + - name: Overview |
| 39 | + href: datalake/notebooks-overview.md |
| 40 | + displayName: data lake |
| 41 | + - name: Run notebooks |
| 42 | + href: datalake/notebooks.md |
| 43 | + displayName: data lake |
| 44 | + - name: Microsoft Sentinel provider class reference |
| 45 | + href: datalake/sentinel-provider-class-reference.md |
| 46 | + displayName: data lake |
| 47 | + - name: Create and manage notebook jobs |
| 48 | + href: datalake/notebook-jobs.md |
| 49 | + displayName: data lake |
| 50 | + - name: Notebook examples for data lake exploration |
| 51 | + href: datalake/notebook-examples.md |
14 | 52 | - name: Plan |
15 | 53 | items: |
16 | 54 | - name: Deployment planning guide |
17 | 55 | href: deploy-overview.md |
18 | 56 | - name: Prerequisites |
19 | 57 | href: prerequisites.md |
20 | 58 | - name: Workspace architecture |
21 | | - items: |
22 | | - - name: Design workspace architecture |
23 | | - href: /azure/azure-monitor/logs/workspace-design?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
| 59 | + items: |
24 | 60 | - name: Review sample workspace designs |
25 | 61 | href: sample-workspace-designs.md |
26 | 62 | - name: Prepare for multiple workspaces |
|
29 | 65 | href: prioritize-data-connectors.md |
30 | 66 | - name: Plan roles and permissions |
31 | 67 | href: roles.md |
| 68 | + displayName: data lake |
32 | 69 | - name: Plan interactive and long-term data retention |
33 | 70 | href: log-plans.md |
34 | 71 | - name: Plan costs |
|
55 | 92 | href: quickstart-onboard.md |
56 | 93 | - name: Connect Microsoft Sentinel to the Defender portal |
57 | 94 | href: /unified-secops-platform/microsoft-sentinel-onboard?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
| 95 | + - name: Onboard to Microsoft Sentinel data lake |
| 96 | + href: datalake/sentinel-lake-onboarding.md |
| 97 | + displayName: data lake |
| 98 | + - name: Set up connectors for the Microsoft Sentinel data lake |
| 99 | + href: datalake/sentinel-lake-connectors.md |
| 100 | + displayName: data lake |
58 | 101 | - name: Configure content |
59 | 102 | href: configure-content.md |
60 | 103 | - name: Set up multiple workspaces |
|
356 | 399 | href: summary-rules.md |
357 | 400 | - name: Aggregate insights from raw data into an Auxiliary table |
358 | 401 | href: summary-rules-tutorial.md |
| 402 | +- name: Manage data |
| 403 | + items: |
| 404 | + - name: Data management overview |
| 405 | + href: manage-data-overview.md |
| 406 | + displayName: table management, tiers, retention, manage data, tables |
| 407 | + - name: Manage tables, tiers, and retention |
| 408 | + href: manage-table-tiers-retention.md |
| 409 | + displayName: table management, tiers, retention, tables |
359 | 410 | - name: Integrate threat intelligence |
360 | 411 | items: |
361 | 412 | - name: Overview |
|
665 | 716 | href: soc-optimization/soc-optimization-reference.md |
666 | 717 | - name: Manage Microsoft Sentinel |
667 | 718 | items: |
| 719 | + |
668 | 720 | - name: Manage costs and billing |
669 | 721 | items: |
670 | 722 | - name: Monitor costs |
|
675 | 727 | href: enroll-simplified-pricing-tier.md |
676 | 728 | - name: Optimize costs with pre-purchase plan |
677 | 729 | href: billing-pre-purchase-plan.md |
678 | | - - name: Manage data retention |
679 | | - href: /azure/azure-monitor/logs/data-retention-configure?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
680 | | - - name: Auxiliary logs use cases |
| 730 | + - name: Data lake use cases |
681 | 731 | href: basic-logs-use-cases.md |
682 | 732 | - name: Manage multiple workspaces |
683 | 733 | items: |
|
695 | 745 | href: multiple-workspace-view.md |
696 | 746 | - name: Manage your intellectual property in Microsoft Sentinel |
697 | 747 | href: mssp-protect-intellectual-property.md |
698 | | - - name: Manage workspace access |
| 748 | + - name: Manage workspace access with resource-context RBAC |
699 | 749 | href: resource-context-rbac.md |
700 | 750 | - name: Set up customer-managed keys |
701 | 751 | href: customer-managed-keys.md |
|
717 | 767 | href: monitor-analytics-rule-integrity.md |
718 | 768 | - name: Auditing Microsoft Sentinel with Azure Activity Logs |
719 | 769 | href: audit-sentinel-data.md |
| 770 | + - name: Audit log for Microsoft Sentinel data lake |
| 771 | + href: datalake/auditing-lake-activities.md |
| 772 | + displayName: data lake |
720 | 773 | - name: Remove Microsoft Sentinel from your workspaces |
721 | 774 | href: offboard.md |
722 | 775 | - name: Build and publish Microsoft Sentinel solutions |
|
757 | 810 | href: aws-s3-troubleshoot.md |
758 | 811 | - name: Reference |
759 | 812 | items: |
760 | | - - name: Service limits |
| 813 | + - name: Microsoft Sentinel service limits |
761 | 814 | href: sentinel-service-limits.md |
| 815 | + - name: Microsoft Sentinel data lake service limits |
| 816 | + href: datalake/sentinel-lake-service-limits.md |
| 817 | + displayName: data lake |
762 | 818 | - name: Microsoft Sentinel REST-API |
763 | 819 | href: /rest/api/securityinsights/ |
764 | 820 | - name: OOTB content centralization changes |
|
0 commit comments