Microsoft Sentinel
Architecture and deployment

Sentinel Solutions Deploy

In brief

The documentation received wording updates, clearer content-type links, expanded ARM terminology, and added guidance and a link for configuring data connectors. Support and content customization instructions were also clarified.

What Defender admins need to know

Administrators have clearer navigation and guidance for managing solutions, content, and data connectors.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security operations administrator, I want to discover, install, and centrally manage out-of-the-box content so that I can efficiently enhance and maintain my security monitoring capabilities.

Prerequisites

In order toTo install, update, andor delete standalone content or solutions in content hub, you need the Microsoft Sentinel Contributor role at the resource group level.

For more information about other roles and permissions supported for Microsoft Sentinel, see Permissions in Microsoft Sentinel.

  1. Search for the solutions or standalone content items that you need. Either select specific values from the filters, or enter a search term into the Search box. Searches use AI to support fuzzy searches and approximate vocabulary.

    When searching, make sure to pressPress ENTER to start the search. The number of search results isResults are limited to 50 items, including both solutions and content items found within solutions. If you don't find what you're looking for, need, refine your search or try refining the search expression or use different filters.

    For more information, see Categories for Microsoft Sentinel out-of-the-box content and solutions.

  2. In the API response, locate the properties.mainTemplate field. This field contains the ARMAzure Resource Manager (ARM) template JSON that defines the solution or template resources.

  3. Deploy the extracted mainTemplate using an ARM template deployment, either through the Rest API, Azure CLI, or PowerShell.

Manage each content type

The following sections provide some tips ondescribe how to work with the different content typesdata connectors, analytics rules, hunting queries, workbooks, parsers, and playbooks as you manage a solution.

Connect a data connector

  1. To customize your hunting query, select the link in the Content name column.

    FromIn the hunting gallery, you can create aselect the ellipses menu to clone of the read-only hunting query template by going to the ellipses menu. Huntingtemplate. Cloned queries created in this way display as itemsappear in the content hub Created content column.

Create a workbook from a template

To customize a workbook createdworkbook, save a copy from a template, create an instance of a workbook.the template.

  1. Select View template to open the workbook and see the visualizations.
  2. Select Save to create an instance of the workbook template.

Find the support model for your content

Each solution and standalone content item explainsshows its support model on its details pane, in the Support box, wherebox on its details pane. The box lists either Microsoft or a partner's name is listed. name. For example:

:::image type="content" source="media/sentinel-solutions-deploy/find-support-details.png" alt-text="Screenshot of where you can find your support model for your solution." lightbox="media/sentinel-solutions-deploy/find-support-details.png":::

When contactingyou contact support, you might need other details about your solution, such as athe publisher, provider, andor plan ID values.for your solution. Find this informationthese details on the details page in the Usage information & support tab.tab of the details page.

:::image type="content" source="media/sentinel-solutions-deploy/usage-support.png" alt-text="Screenshot of usage and support details for a solution.":::

Next steps

Many solutions include data connectors that you need to configure so that you can start ingesting your data into Microsoft Sentinel. Each data connector has its own set of requirements that are detailed on the data connector page in Microsoft Sentinel.

For more information, see Connect your data source.

Related content