Description
If you're using Azure Sentinel as a SIEM integration, you have the option to integrate that with ConcealBrowse. This allows metrics and data collected by Conceal can be seamlessly transferred into Azure Sentinel. This article will guide you through integrating Azure Sentinel with ConcealBrowse.
Before you begin:
In your Azure Sentinel instance you will need to create a Workspace ID and an API Key to enter to the Conceal dashboard.
- Open your workspace in the Azure portal
- Then select Agents management, click arrow to expand Log Analytics agent instructions. This is where you will find the parameters needed - Workspace ID and API Key.
Procedure
- Navigate within a web browser to https://dashboard.conceal.io and login if necessary.
- Click on the section labeled Plugins on the left hand menu.
- Scroll down and in the PostProcess section, locate the Azure Sentinel tile and click the button labeled Configure.
- You will need to copy your Azure Workspace ID and your Azure Sentinel Shared API Key from your Azure Sentinel instance and paste in the appropriate fields in the Conceal dashboard. Click the Enabled checkbox, Save Settings, Close.
- The plugin should now show Enabled meaning you have Azure Sentinel configured with ConcealBrowse and the data from Conceal dashboard should push into your Azure Sentinel instance.
Video Reference:
*Never hesitate to contact your Customer Success Manager for any questions or concerns. You may also open a support ticket at support.conceal.io by scrolling to the bottom and clicking Submit a request.
Related to:
0
0
Was this article helpful?
0 out of 0 found this helpful
Articles in this section
- Integrating Wazuh with ConcealBrowse
- Integrating Syslog with ConcealBrowse
- Integrating Azure Sentinel with ConcealBrowse
- Integrating Devo with ConcealBrowse
- How to push pre-process results into a custom post-process webhook
- Reading data in Splunk
- Reading data in Elasticsearch
- Elasticsearch Integration with ConcealBrowse
- Splunk integration with ConcealBrowse
- Elasticsearch configuration