New data lake in Microsoft Sentinel

New data lake in Microsoft Sentinel

Centralize, retain, and query high-volume, long-term security data across Microsoft and third-party sources for up to 12 years using Microsoft Sentinel's new unified data lake. Correlate signals, run advanced analytics, and perform forensic investigations from a single copy of data—without costly migrations or data silos. Detect persistent, low-and-slow attacks with greater visibility, automate responses using scheduled jobs, and generate predictive insights by combining Copilot, KQL, and machine learning.

Vandana Mahtani, Microsoft Sentinel Principal Product Manager shows how to uncover long-running threats, streamline investigations, and automate defenses—all within a unified, AI-powered SIEM experience.

► QUICK LINKS:

00:00 - Microsoft Sentinel Data Lake

01:49 - Data Management

02:46 - Table Management

03:36 - Data Lake exploration

04:17 - Advanced Hunting

05:23 - Query retention data

06:16 - Automate threat detection

07:18 - Move from reactive to predictive

08:50 - Wrap up

► Link References

Check out https://aka.ms/SentinelDataLake

► Unfamiliar with Microsoft Mechanics?

As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.

• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries

• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog

• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast

► Keep getting this insider knowledge, join us on social:

• Follow us on Twitter: https://twitter.com/MSFTMechanics

• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/

• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/

• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(100)

Windows 365: Five Years In, See What's New

Windows 365: Five Years In, See What's New

An AI agent works inside your Windows 365 Cloud PC from a Teams chat on your phone — finding downloaded files, editing documents, and drafting emails with your laptop lid closed. Microsoft Scout, a ne...

21 Aug 15min

Build your first Power App from data in seconds

Build your first Power App from data in seconds

Build a fully working model-driven app from your existing Dataverse, SharePoint, or SQL data in under a minute — screens, navigation, and forms included. Generate new pages from a natural language pro...

16 Jul 7min

Microsoft Entra Suite hands-on tour of identity and network access protections

Microsoft Entra Suite hands-on tour of identity and network access protections

Unify identity and network access controls. Enforce least privilege access across every app and resource. Wire lifecycle workflows directly to your HR system to strip stale permissions on role changes...

15 Jul 9min

New agentic platform in Dynamics 365 for Sales and Service

New agentic platform in Dynamics 365 for Sales and Service

Qualify a lead, close a case, or walk into a renewal meeting fully briefed, all from the sales and service agents built into Dynamics 365. Ask a question and pull a grounded answer straight from your ...

14 Jul 10min

Tokenomics | The new AI currency & your options explained

Tokenomics | The new AI currency & your options explained

Control what you're billed on. Tokens are the currency of AI, and how you design your app determines how many you spend. Compress conversation history instead of resending it raw, cap output tokens wi...

9 Jul 14min

Deploy Windows updates to counter AI-discovered threats

Deploy Windows updates to counter AI-discovered threats

The speed that AI can now discover and exploit vulnerabilities means that our defenses also need to adjust. For the devices that you manage where you can afford to tighten deployment timelines, we'll ...

7 Jul 3min

Zero Trust security for AI agents

Zero Trust security for AI agents

Apply Zero Trust controls to every AI agent in your environment across identity, tool usage, and data access. Extend Conditional Access in Microsoft Entra to evaluate every agent authorization request...

2 Jul 10min

Secure containers from code to runtime | Microsoft Defender

Secure containers from code to runtime | Microsoft Defender

Secure containerized apps end-to-end using Microsoft Defender for Cloud. Correlate cross-cloud attacks into a single incident, catch runtime threats that image scanning misses, and block vulnerable im...

29 Jun 9min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
stopp-verden
popradet
nokon-ma-ga
fotballpodden-2
bt-dokumentar-2
lydartikler-fra-aftenposten
rss-espen-lee-usensurert
det-store-bildet
aftenbla-bla
hanna-de-heldige
dine-penger-pengeradet
rss-gukild-johaug
rss-ness
e24-podden
rss-penger-polser-og-politikk
frokostshowet-pa-p5