Skip to content

Commit db7417d

Browse files
authored
Merge pull request #2288 from sbreingold-ms/wi-541835-mdc-ep-64
wi-541835-mdc-ep-64
2 parents 2f96dc7 + f695b93 commit db7417d

2 files changed

Lines changed: 38 additions & 0 deletions

File tree

articles/defender-for-cloud/TOC.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1490,6 +1490,9 @@
14901490
- name: Integrate CLI with CI/CD pipelines
14911491
DisplayName: Defender for Cloud CLI, CI/CD pipelines
14921492
href: episode-fifty-nine.md
1493+
- name: Storage aggregated logs
1494+
DisplayName: Storage aggregated logs, Advanced Hunting, CloudStorageAggregatedEvents
1495+
href: episode-sixty-four.md
14931496
- name: Microsoft Defender for IoT documentation
14941497
href: /azure/defender-for-iot/
14951498
- name: Azure security documentation
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
---
2+
title: Storage aggregated logs
3+
description: Learn about storage aggregated logs and how to investigate storage activity in XDR Advanced Hunting.
4+
ms.topic: reference
5+
ms.date: 09/26/2025
6+
---
7+
8+
# Storage aggregated logs
9+
10+
**Episode description**: In this episode of Defender for Cloud in the Field, Lior Tsalovich joins Yuri Diogenes to talk about storage aggregated logs in XDR's Advanced Hunting. Lior explains the new CloudStorageAggregatedEvents table available in Microsoft Defender XDR's Advanced Hunting experience. She explains how aggregated storage activity logs can help SOC Teams during an investigation. Lior also demonstrates how to use Defender XDR advanced hunting to query data using CloudStorageAggregatedEvents table.
11+
12+
> [!VIDEO https://aka.ms/docs/player?id=4720b59c-2c9e-4908-982c-9dab1fe0bca4]
13+
14+
- [01:20](/shows/mdc-in-the-field/storage-aggregated-logs#time=01m20s) - Current challenges faced by SOC Teams and how this feature helps
15+
- [02:50](/shows/mdc-in-the-field/storage-aggregated-logs#time=02m50s) - Storage investigation gaps addressed by this solution
16+
- [05:09](/shows/mdc-in-the-field/storage-aggregated-logs#time=05m09s) - Data aggregation and enhancement
17+
- [06:16](/shows/mdc-in-the-field/storage-aggregated-logs#time=06m16s) - Other scenarios covered by this feature
18+
- [08:42](/shows/mdc-in-the-field/storage-aggregated-logs#time=08m42s) - Demonstration
19+
20+
## Recommended resources
21+
22+
- Learn more about [managing security policies](tutorial-security-policy.md).
23+
- Subscribe to [Microsoft Security on YouTube](https://www.youtube.com/playlist?list=PL3ZTgFEc7LysiX4PfHhdJPR7S8mGO14YS).
24+
- Join our [Tech Community](https://aka.ms/SecurityTechCommunity).
25+
- For more about [Microsoft Security](https://msft.it/6002T9HQY).
26+
27+
- Follow us on social media:
28+
29+
- [LinkedIn](https://www.linkedin.com/showcase/microsoft-security/posts/)
30+
- [X](https://x.com/msftsecurity)
31+
32+
## Next steps
33+
34+
> [!div class="nextstepaction"]
35+
> [New AWS connector in Microsoft Defender for Cloud](episode-one.md)

0 commit comments

Comments
 (0)