Contoso-Hotels-Security-old / LogIngestion

LogIngestion and Fusion
6 stars 2 forks source link

Create sentinel workspace using new onboarding api #1

Open camilo86 opened 1 year ago

camilo86 commented 1 year ago

Changes

Use Sentinel onboarding API to create new sentinel workspaces

Why

Sentinel workspaces are LA workspaces with many custom features enabled on top. Doing this manually can be error prone. For example, the current implementation does not enable anomalies which is required for many analytic rules to work properly.

Onboarding API takes care of setting up the workspace with the correct settings.

Some more information about the onboarding API: https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-azure-sentinel-new-onboarding-offboarding-api/ba-p/2640471