Microsoft Sentinel
Cloud and workloads

Map Data Fields to Microsoft Sentinel Entities

In brief

The article now explicitly covers adding or changing entity mappings in existing analytics rules and while creating new scheduled analytics rules. It also updates formatting, metadata, and related-content links.

What Defender admins need to know

Administrators can use the revised instructions; no configuration change or migration is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Map data fields to entities in Microsoft Sentinel

Entity mapping is an integral part of the configuration of scheduled analytics rules. It enriches the rules' output (alerts and incidents) with essential information that serves as the building blocks of any investigative processes and remedial actions that follow.

TheUse the following procedure is part of the analytics rule creation wizard. It's treated here independently to address the scenario of addingadd or changingchange entity mappings in an existing analytics rule, or while creating a new scheduled analytics rule.

:::image type="content" source="media/map-data-fields-to-entities/choose-entity-type.png" alt-text="Choose an entity type":::
  1. Select an identifier for the entity. Identifiers are attributes of an entity that can sufficiently identify it. Choose one from the Identifier drop-down list, and then choose a data field from the Value drop-down list that will correspond to the identifier. With some exceptions, the Value list is populated by the data fields in the table defined as the subject of the rule query.

    You can define up to three identifiers for a given entity mapping. Some identifiers are required, others are optional. You must choose at least one required identifier. If you don't, a warning message will instruct you which identifiers are required. For best results—for maximum unique identification—you should use strong identifiers whenever possible, and using multiple strong identifiers will enable greater correlation between data sources. See the full list of available entities and identifiers.

    :::image type="content" source="media/map-data-fields-to-entities/map-entities.png" alt-text="Map fields to entities":::

  2. Select Add new entity to map more entities. You can define up to ten10 entity mappings in a single analytics rule. You can also map more than one of the same type. For example, you can map two IP entities, one from a source IP address field and one from a destination IP address field. This wayBy mapping both fields, you can track them both.both IP entities.

    If you change your mind, or if you made a mistake, you can remove an entity mapping by clicking the trash can icon next to the entity drop-down list.

  3. When you have finished mapping entities, click the Review and create tab. Once the rule validation is successful, click Save.

Notes on the new version

The entity mapping experience was updated from an older version. Keep the following backward-compatibility details in mind:

  • As the new version is now generally available (GA), the feature-flag workaround to use the old version is no longer available.

  • If you had previously defined entity mappings for this analytics rule using the old version, they will be automatically converted to the new version.

Related content

  • Get the complete picture on scheduled query analytics rulesCreate a scheduled analytics rule from scratch.
  • Learn more about Entities in Microsoft Sentinel.