Azure Sentinel – Watchlist Enhancements

News Informatique

Azure Sentinel – Watchlist Enhancements

Azure Sentinel Watchlists provides the ability to quickly import IP addresses, file hashes, etc. from csv files into your Azure Sentinel workspace. Then utilize the watchlist name/value pairs for joining and filtering for use in alert rules, threat hunting, workbooks, notebooks and for general queries.

Watchlist Updating Functionality

The new watchlist UI encompasses the following functionality:

  • Add new watchlist items or update existing watchlist items.
  • Select and update multiple watchlist items at once via an Excel-like grid.
  • Add/remove columns from the watchlist update UI view for better usability.

How to update watchlist

From the Azure portal, navigate to Azure Sentinel > Configuration > Watchlist

thumbnail image 1 of blog post titled 
	
	
	 
	
	
	
				
		
			
				
						
							What’s New: Azure Sentinel Update Watchlist UI Enhancements

Select a Watchlist, then select Edit Watchlist Items

thumbnail image 2 of blog post titled 
	
	
	 
	
	
	
				
		
			
				
						
							What’s New: Azure Sentinel Update Watchlist UI Enhancements

Select > Add New, update watchlist parameters

thumbnail image 3 of blog post titled 
	
	
	 
	
	
	
				
		
			
				
						
							What’s New: Azure Sentinel Update Watchlist UI Enhancements

Source

https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-update-watchlist-ui-enhancements/ba-p/2451476

No Comments

Add your comment