wwlpublish Data normalization in Microsoft Sentinel - Training
- By the end of this module, you'll be able to
use ASIM parserstoidentify threatswithin your organization and create bothASIM parsersandparameterized KQLfunctions.
‣
‣
Introduction
‣
Understand data normalization
‣
Use ASIM Parsers
‣
Understand parameterized KQL functions
‣
Create an ASIM Parser
‣
Configure Azure Monitor Data Collection Rules
‣
Knowledge check
‣