wwlpublish Data normalization in Microsoft Sentinel - Training
- By the end of this module, you'll be able to
use ASIM parsers
toidentify threats
within your organization and create bothASIM parsers
andparameterized KQL
functions.
‣
‣
Introduction
‣
Understand data normalization
‣
Use ASIM Parsers
‣
Understand parameterized KQL functions
‣
Create an ASIM Parser
‣
Configure Azure Monitor Data Collection Rules
‣
Knowledge check
‣