Microsoft Sentinel
Cloud and workloads

Defender portal

In brief

The article now provides separate steps for viewing existing analytics rule templates in the Defender portal and Azure portal, and updates the procedure wording and metadata.

What Defender admins need to know

No action is required. Administrators can follow the steps for their chosen portal.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to create scheduled analytics rules from templates so that I can efficiently monitor and detect anomalies in my data.

Microsoft makes a vast array of analytics rule templates available to you through the many solutions provided in the Content hub, and strongly encourages you to use them to create your rules. The queries in scheduled rule templates are written by security and data science experts, either from Microsoft or from the vendor of the solution providing the template.

This articleThe following procedure shows you how to create a scheduled analytics rule usingfrom a template.

[!INCLUDE unified-soc-preview]

Defender portal

Use the following steps to view existing analytics rule templates in the Defender portal.

  1. From the Microsoft Defender navigation menu, expand Microsoft Sentinel, then Configuration. Select Analytics.

  2. On the Analytics screen, select the Rule templates tab.

Azure portal

Use the following steps to view existing analytics rule templates in the Azure portal.

  1. From the Configuration section of the Microsoft Sentinel navigation menu, select Analytics.

  2. On the Analytics screen, select the Rule templates tab.

    When you get to the end of the rule creation wizard, Microsoft Sentinel creates the rule. The new rule appears in the Active rules tab.

    Repeat the processthese rule-creation steps to create more rules. For more details on how to customize your rules in the rule creation wizard, see Create a custom analytics rule from scratch.