Microsoft Sentinel
Cloud and workloads

Modify content to use the Advanced Security Information Model (ASIM)

In brief

The page metadata was updated, and a new section titled “Convert Microsoft Sentinel content to use ASIM normalized data” was added.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to modify custom analytics rules to use the Advanced Security Information Model (ASIM) so that I can leverage normalized data for more efficient and consistent threat detection.

Modify content to use the Advanced Security Information Model (ASIM)

Convert Microsoft Sentinel content to use ASIM normalized data

Normalized security content in Microsoft Sentinel includes analytics rules, hunting queries, and workbooks that work with unifying normalization parsers.

You can find normalized, out-of-the-box content in Microsoft Sentinel galleries and Microsoft Sentinel solutions catalog, create your own normalized content, or modify existing, custom content to use normalized data.