Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Hands On: Azure Sentinel Cloud SIEM & SOAR
Rating: 2.6 out of 5(32 ratings)
225 students

Hands On: Azure Sentinel Cloud SIEM & SOAR

Learn Embrace first of its kind Cloud Based SIEM & SOAR making Azure different from other public cloud providers.
Created byVipul Dabhi
Last updated 10/2025
English

What you'll learn

  • Students will understand the first of its kind Azure cloud provisoned SAAS service called as Sentinel with complete hands on,
  • Ability to comprehensively implement Azure Sentinel along wit practical walkthrough and Interview preparation.
  • They will understand What Azure Sentinel is, how its different from other SIEM tools.
  • Will get thourough understanding on Data Connectors
  • Will be getting insight og Kusto Query Language(KQL)
  • Pactical hands on for Native Connector to Azure Sentinel like Azure Security Center, Azure Activity etc.
  • Pactical hands on for integrating external data connections like Firewall(Checkpoint,Paloalto), Antivirus(Symantec,Trendmicro)
  • Implementation & Administration of Syslog Server to ingest log intermediatley
  • Understanding Analytics Part via Investigation for various Incidents.
  • Handling and responding to the Incident.
  • Categorization of Incidents in Low,High,Medium etc and its relevance.
  • Understanding Playbooks,Workbooks & Logic apps

Course content

9 sections22 lectures6h 15m total length
  • Azure Sentinel Implementation & Administration13:08

    Learn to implement and administer Azure Sentinel, a cloud-native SIEM and SOAR, with data ingestion, analytics, threat intelligence, playbooks, and automated incident response.

  • Why Azure Sentinel7:27

    Explore why Azure Sentinel enables cloud-based SIEM and SOAR, detailing data ingestion, alert management, threat analytics with artificial intelligence, and automated incident response for security operations.

  • Hands On: Adding Azure Sentinel To Log Analytics Workspace & Walkthrough12:12

    Learn how to add Azure Sentinel to a Log Analytics workspace, onboard data from endpoints and networks, and use rules, incidents, and orchestration for automated detection and response.

  • Hands On: Kusto Query Language (KQL)10:29

    Explore how the Kusto query language (KQL) structures data with schema, tables, and columns to enable readable, query-based analysis in Azure Sentinel's SIEM and SOAR environments.

  • Creating Sentinel Data Source & Discussing Pricing Of Azure Sentinel10:38
  • Hands On: Checkpoint Data Connector for Ingesting Checkpoint Logs18:27

    Learn to set up the checkpoint data connector to ingest logs into a central Sentinel workspace, covering architecture, log flow, port checks, and deleting seven days old logs.

  • Hands On : If You Encounter A Bad Sentinel Design15:57
  • Integrating Trendmicro Antivirus Part 16:06

    Integrate Trend Micro antivirus with Azure Sentinel by deploying Trend Micro agents on endpoints, forwarding logs to a central Deep Security Manager, and using connectors to feed dashboards and alerts.

  • Hands On: Integrating Trendmicro Antivirus uisng Azure Function Part 22:54

    Practice integrating Trend Micro Antivirus with Azure Function in a Sentinel environment, saving and naming the function, managing logs, and enabling security workflows for SIEM and SOAR.

  • Azure Sentinel Architecture Design Consideration10:18
  • Azure Sentinel SOAR Capabilities9:04

    Discover Azure Sentinel SOAR capabilities for security orchestration, automation, and response using playbooks and logic apps to automate incident response and data migration.

Requirements

  • This course is complete bundle in itself around Implementation & Administration of Azure Sentinel.
  • Some Background in SIEM & SOAR,
  • AZ-900 & AZ-500 which is Azure fundamentals & Azure Security Specialisation will be helpful to make most out of this course.

Description

Cloud based SIEM like Sentinel is the answer to the problems which are faced by mainstream SIEM tools with:

1. Efficient Automation by logic apps and playbooks.

2.Co-relation powered by Machine Learning Algorithms like Fusion.

3.Scalable with inbuilt Data Connectors and ability to design SaaS solution is always scalable.

4.Focused in noise reduction and focusing or reaching and remediation to those which can result in increase/breach of attack surface.

5.Built In the cloud .

6.Scope grows everyday hence integration of threat intel to handle them.

Who this course is for:

  • Cloud Security Professionals
  • Cyber Security Professionals
  • SOC Managers
  • SOC Operations
  • SIEM & SOAR
  • Cloud SIEM