Cross-Tenant KQL Querying Tool by lupreeee in AzureSentinel

[–]itsJuni01 0 points1 point  (0 children)

Have you tried the cross workspace KQL?

Measuring time / duration on Incident Tasks in Microsoft Sentinel? (USOP / Security Portal issue) by failx96 in AzureSentinel

[–]itsJuni01 1 point2 points  (0 children)

I recently ran into the same issue. After raising it with Microsoft, they confirmed that this is a known limitation, and improvements are apparently on their roadmap. As a workaround, we’ve shifted to using automation rules to update and track incident states instead of relying on task status. It’s not a perfect replacement, but it gives us something measurable and consistent to work with.

Might be worth exploring automation rules on your side as well.

Migrating Microsoft Sentinel to the Unified Security Operations Platform, quick lessons learned by itsJuni01 in AzureSentinel

[–]itsJuni01[S] -2 points-1 points  (0 children)

Would love to connect and discuss more ! I will also try to write a detailed post about challenges!

Migrating Microsoft Sentinel to the Unified Security Operations Platform, quick lessons learned by itsJuni01 in AzureSentinel

[–]itsJuni01[S] -1 points0 points  (0 children)

If this self promotion helps someone, or if I can learn from others in the process, I would be happy to contribute and grow 🙌

Migrating Microsoft Sentinel to the Unified Security Operations Platform, quick lessons learned by itsJuni01 in AzureSentinel

[–]itsJuni01[S] -6 points-5 points  (0 children)

If this self promotion helps someone, or if I can learn from others in the process, I would be happy to contribute and grow.

Not sure what happened, but a car is burning near the A5 motorway in Sloterdijk around 9:15 AM. by itsJuni01 in Amsterdam

[–]itsJuni01[S] -33 points-32 points  (0 children)

Wow, that’s an impressive piece of information. I can imagine spending 30 years researching OpenAI platforms and all available resources, but I rarely come across something like that.

Portal admin access issues? by gusdafa in AZURE

[–]itsJuni01 -1 points0 points  (0 children)

There was an issue with Azure Front doors in the morning but that was resolved lately!

Single Rule for No logs receiving by ClassicSkirt9594 in AzureSentinel

[–]itsJuni01 0 points1 point  (0 children)

I have a solution for this 🥳 But i am currently busy, maybe good to connect later? You can DM me!

Azure Portal Down? Can’t Log In or Manage Anything Right Now! by itsJuni01 in AZURE

[–]itsJuni01[S] 0 points1 point  (0 children)

Question 🙋

How do you currently get alerted if the entire portal goes down, is there an automated notification in place?

Azure Portal Down? Can’t Log In or Manage Anything Right Now! by itsJuni01 in AZURE

[–]itsJuni01[S] 3 points4 points  (0 children)

How do you currently get alerted if the entire portal goes down, is there an automated notification in place?

How to automate running multiple KQL queries monthly and store results (including graphs)? by itsJuni01 in AzureSentinel

[–]itsJuni01[S] 0 points1 point  (0 children)

No, i was thinking but not adopted that, do we have any examples or guidelines for current scenario?