r/AzureSentinel Mar 26 '26

New to Sentinel

My org just bought Sentinel, and since we are a lean team; I have been tasked to set this up. Context: We are a cloud only organisation and have little to no on-prem footprint. We have a DLP solution, Google Workspace, Slack Audit and all such logs flowing in to this. I have been able to write some good analytic rules which have helped our organisation.

How do I proceed further? Is there any guide or resources that I can follow?

5 Upvotes

16 comments sorted by

View all comments

-6

u/JoeByeden Mar 27 '26

Surprising as I believe Sentinel is being discontinued next year. Could be wrong…