Microsoft Sentinel
Cloud and workloads

Use the SIEM Migration Experience

In brief

The article now explicitly instructs users to export detection rules, confirms that Security Copilot must be enabled, and clarifies analysis status, matched detections, recommendations, and reports. It also states that the tool does not consume SCUs or generate SCU-based charges.

What Defender admins need to know

Administrators using the experience can follow clearer setup and workflow guidance. No immediate action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Export detection rules from your current SIEM

Export your existing detection rules from your current SIEM so the SIEM migration experience can analyze them.

Splunk

In the Search and Reporting app in Splunk, run the following query:

  1. When prompted, enter your QRadar authorized service token. The token input is hidden. Don't include the token in the command line.
  2. When the script finishes, upload the generated qradar_rules_YYYYMMDDHHMMSS.csv file in the SIEM migration experience, then select Next.

For more information about the QRadar migration data collector script and its parameters, see the QRadar migration data collector README.

Troubleshoot QRadar exports

:::image type="content" source="./media/siem-migration/select-siem.png" alt-text="Screenshot of the UI asking the user to select the SIEM they're migrating from.":::
  1. Upload the configuration data that you exported (see Export detection rules from your current SIEM) and select Next.

    The migration tool analyzes the export and identifies the number of data sources and detection rules in the file you provided. Use this information to confirm that you have the right export.

    :::image type="content" source="./media/siem-migration/select-workspace.png" alt-text="Screenshot of the UI asking the user to select a workspace.":::

    The migration tool maps the detection rules to Microsoft Sentinel data sources and detection rules. If there are no recommendations in the workspace, recommendations are created. If there are existing recommendations, the SIEM migration tool deletes and replaces them with new ones.

    :::image type="content" source="./media/siem-migration/getting-ready.png" alt-text="Screenshot of the migration tool getting ready to analyze the rules.":::

    :::image type="content" source="./media/siem-migration/setup-analysis-status.png" alt-text="Screenshot of the SIEM Set-up analysis status showing the progress of the analysis.":::

    ThisThe SIEM setup analysis status page doesn't refresh automatically. To see the latest status, close and reopen the page.

    The analysis is complete when all three check marks are green. If the three checkmarks are green but there are no recommendations, it means that no matches were found for your rules.

    :::image type="content" source="./media/siem-migration/status-complete.png" alt-text="Screenshot showing all three check marks green indicating analysis is complete.":::

    When the SIEM migration analysis completes, the migration tool generates use-case-based recommendations, grouped by Content Hub solutions. You can also download a detailed report of the analysis. The report contains a detailed analysis of recommended migration jobs, including Splunk and QRadar rules that don't have a good match, weren't detected, or aren't applicable.

    :::image type="content" source="./media/siem-migration/recommendations.png" alt-text="A screenshot of recommendations generated by the migration tool." lightbox="./media/siem-migration/recommendations.png":::

    :::image type="content" source="./media/siem-migration/recommendation-card.png" alt-text="A screenshot of a recommendation card." lightbox="./media/siem-migration/recommendation-card.png":::

    The SIEM migration tool matches Splunk and QRadar rules to out-of-box Microsoft Sentinel data connectors, out-of-box Microsoft Sentinel detection rules, and Defender XDR native detections. The connectors tab shows the data connectors matched to the rules from your SIEM and the status (connected or not disconnected). If the connector you want to use isn't already connected, you can connect from the connector tab. If a connector isn't installed, go to the Microsoft Sentinel Content hub and install the solution that contains the connector you want to use.

    :::image type="content" source="./media/siem-migration/connectors.png" alt-text="Screenshot of Microsoft Sentinel data connectors matched to Splunk or QRadar rules.":::

Enable detection rules

After reviewing the matched results, you can enable the recommended Microsoft Sentinel detection rules or review Defender XDR native detections.

Microsoft Sentinel detection rules

When you select a recommended detection rule, the rulesrule details side panel opens and you can view the rulesrule template details.

:::image type="content" source="./media/siem-migration/rule-details.png" alt-text="Screenshot of the rule details side panel." lightbox="./media/siem-migration/rule-details.png":::

:::image type="content" source="./media/siem-migration/compare-rules.png" alt-text="Screenshot of the comparison between Splunk SPL rule and Microsoft Sentinel KQL.":::

Enable detection is only enabled if the data connector is installed and configured to stream logs.

Defender XDR native detections

Defender XDR native detections are built-in detection logic that generate alerts, which are then correlated into incidents. The SIEM migration tool maps Splunk and QRadar rules to these native detections. Matched Defender XDR native detections are in active status. This type of detection doesnDefender XDR native detections don't require Microsoft Sentinel data connectors to be installed, configured, and connected.

:::image type="content" source="./media/siem-migration/defender-detections.png" alt-text="Screenshot of the list of matched Defender XDR native detections." lightbox="./media/siem-migration/defender-detections.png":::