Token导航 LogoToken导航TokenDH.com
云服务external-servicegithub未标认证来源可访问许可证需确认审计通过

azure-sentinelAzure sentinel 部署

Agent Skill

用于辅助云资源、部署、容器、基础设施和运维自动化任务。它适合让 Agent 检查配置、整理部署步骤、分析资源状态、生成排障思路或辅助云服务接入。使用时需要明确目标环境、账号权限、区域和资源组,区分本地测试与生产操作;涉及删除资源、重启服务、修改网络或权限配置时,应先确认影响范围。

总安装

879

周安装

37

GitHub Stars

519

下载量

308
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:azure-sentinel(Azure sentinel 部署)
来源仓库:https://github.com/microsoftdocs/agent-skills
仓库路径:skills/azure-sentinel
安装命令:
npx skills add https://github.com/microsoftdocs/agent-skills --skill azure-sentinel
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/microsoftdocs/agent-skills --skill azure-sentinel

简介

提供 Azure Sentinel 安全信息与事件管理(SIEM)的专业指导与排错支持。

  • 适用于 SOC 团队构建威胁狩猎流程,关联日志源并自动化响应剧本。
  • 协助配置数据连接器、KQL 查询和 Playbook 触发条件,提升检测效率。
  • 需确保 Log Analytics 工作区已启用,并为相关服务分配适当的读取权限。
  • azure-sentinel 属于云服务类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Azure Sentinel Skill

This skill provides expert guidance for Azure Sentinel. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file
IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L48Diagnosing and fixing Microsoft Sentinel ingestion, connector, KQL/data lake, analytics rule (auto-disable), MCP tools, and SAP/AWS/Blob/CEF/Syslog integration issues.
Best PracticesL49-L75Best practices for SOC operations in Microsoft Sentinel: rule tuning, automation/playbooks, incident tasks/metrics, watchlists, data collection, solution lifecycle, and monitoring/health.
Decision MakingL76-L112Planning Sentinel deployments, pricing, and data tiers; choosing connectors and content; and migrating detections, automation, and historical data from MMA, ArcSight, QRadar, and Splunk.
Architecture & Design PatternsL113-L126Architecting Sentinel deployments: multi-workspace/tenant patterns, MSSP setups, SOAR automation, BCDR/resiliency, cross-workspace data/incident ops, SAP, ML models, and Jupyter-based hunting.
Limits & QuotasL127-L138Limits, quotas, pricing, and retention tiers for Sentinel data, search jobs, watchlists, MCP servers, ASIM, and workspace removal impacts
SecurityL139-L154Security configuration for Microsoft Sentinel: RBAC and roles, row-level/resource-context access, playbook auth/restrictions, encryption keys, audit logs, SAP roles/params, and network/attack protections.
ConfigurationL155-L283Configuring Microsoft Sentinel data connectors, retention, analytics/automation rules, ASIM schemas, UEBA, SAP/Power Platform content, data lake, MCP tools, and health/auditing settings.
Integrations & Coding PatternsL284-L336APIs, connectors, and code patterns for ingesting data, threat intel, and incidents into Sentinel, querying the data lake/graphs, and integrating with playbooks, MCP, Teams, Power BI, and Logic Apps
DeploymentL337-L360Deploying and managing Microsoft Sentinel solutions and content (CI/CD, ARM, content hub, marketplace) and specialized connectors/agents for SAP, Power Platform, Dynamics, Azure Stack Hub, and hunting notebooks.

Troubleshooting

TopicURL
Troubleshoot Microsoft Sentinel AWS S3 connector problemshttps://learn.microsoft.com/en-us/azure/sentinel/aws-s3-troubleshoot
Troubleshoot Microsoft Sentinel Azure Storage Blob connectorhttps://learn.microsoft.com/en-us/azure/sentinel/azure-storage-blob-connector-troubleshoot
Troubleshoot Sentinel CEF and Syslog AMA ingestion issueshttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-troubleshooting
Troubleshoot KQL queries and jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-troubleshoot
Best practices and troubleshooting for Sentinel MCP toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/troubleshoot-sentinel-mcp
Troubleshoot Sentinel SAP data connector agenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-deploy-troubleshoot
Troubleshoot Sentinel analytics rules and AUTO DISABLEDhttps://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules
Troubleshoot Microsoft Sentinel solution ingestion issueshttps://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-sentinel-solutions

Best Practices

TopicURL
Audit and track Sentinel incident task changeshttps://learn.microsoft.com/en-us/azure/sentinel/audit-track-tasks
Implement Sentinel automation rules for SOAR operationshttps://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules
Automate Sentinel response to compromised users with playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/tutorial-respond-threats-playbook
Apply operational best practices for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/best-practices
Apply data collection best practices in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/best-practices-data
Apply fine-tuning recommendations to Sentinel ruleshttps://learn.microsoft.com/en-us/azure/sentinel/detection-tuning
Use ASIM-based essential domain solutions in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/domain-based-essential-solutions
Reduce false positives in Microsoft Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/false-positives
Standardize Sentinel incident handling with taskshttps://learn.microsoft.com/en-us/azure/sentinel/incident-tasks
Handle data ingestion delay in Sentinel ruleshttps://learn.microsoft.com/en-us/azure/sentinel/ingestion-delay
Use Sentinel incident metrics to manage SOC performancehttps://learn.microsoft.com/en-us/azure/sentinel/manage-soc-with-incident-metrics
Update SOC and analyst processes for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-security-operations-center-processes
Monitor health and integrity of Microsoft Sentinel analytics ruleshttps://learn.microsoft.com/en-us/azure/sentinel/monitor-analytics-rule-integrity
Monitor and optimize Sentinel scheduled analytics rule executionhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-optimize-analytics-rule-execution
Protect MSSP intellectual property in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/mssp-protect-intellectual-property
Apply operational recommendations for Microsoft Sentinel SOCshttps://learn.microsoft.com/en-us/azure/sentinel/ops-guide
Configure Sentinel SAP detections and threat protectionhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deployment-solution-configuration
Monitor Zero Trust TIC 3.0 with Sentinel solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution
Manage lifecycle of deprecated Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution-deprecation
Apply quality guidelines to Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solution-quality-guidance
Use Sentinel watchlists to enrich and correlate eventshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists
Maintain and edit Microsoft Sentinel watchlists safelyhttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-manage
Use Sentinel incident tasks in analyst workflowshttps://learn.microsoft.com/en-us/azure/sentinel/work-with-tasks

Decision Making

TopicURL
Plan and execute migration from MMA to AMA for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ama-migrate
Decide and migrate Sentinel alert-trigger playbooks to automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/automation/migrate-playbooks-to-automation-rules
Choose when to use Microsoft Sentinel data lake tierhttps://learn.microsoft.com/en-us/azure/sentinel/basic-logs-use-cases
Plan and estimate Microsoft Sentinel pricing and billinghttps://learn.microsoft.com/en-us/azure/sentinel/billing
Analyze and optimize Microsoft Sentinel cost and billinghttps://learn.microsoft.com/en-us/azure/sentinel/billing-monitor-costs
Use Microsoft Sentinel prepurchase plans to save costshttps://learn.microsoft.com/en-us/azure/sentinel/billing-pre-purchase-plan
Reduce Microsoft Sentinel costs with product featureshttps://learn.microsoft.com/en-us/azure/sentinel/billing-reduce-costs
Choose and configure Sentinel connectors for Cisco ASA/FTDhttps://learn.microsoft.com/en-us/azure/sentinel/cisco-ftd-firewall
Compare Sentinel analytics rules vs Defender custom detectionshttps://learn.microsoft.com/en-us/azure/sentinel/compare-analytics-rules-custom-detections
Assess Sentinel connector data type support by cloudhttps://learn.microsoft.com/en-us/azure/sentinel/data-type-cloud-support
Choose between KQL jobs, summary rules, and search jobshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs-summary-rules-search-jobs
Plan side-by-side deployment with existing SIEMhttps://learn.microsoft.com/en-us/azure/sentinel/deploy-side-by-side
Enroll Sentinel workspaces in simplified pricing tiershttps://learn.microsoft.com/en-us/azure/sentinel/enroll-simplified-pricing-tier
Check Microsoft Sentinel feature availability by Azure cloudhttps://learn.microsoft.com/en-us/azure/sentinel/feature-availability
Plan Sentinel deployment for geography and data residencyhttps://learn.microsoft.com/en-us/azure/sentinel/geographical-availability-data-residency
Choose data tiers and retention for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/manage-data-overview
Use Microsoft Sentinel within the Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-sentinel-defender-portal
Plan and phase a migration to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration
Migrate ArcSight SOAR automation to Sentinel rules and playbookshttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-automation
Map and migrate ArcSight detection rules to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-detection-rules
Export ArcSight historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-arcsight-historical-data
Choose an Azure target platform for Sentinel historical datahttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-target-platform
Select a data ingestion tool for Sentinel historical logshttps://learn.microsoft.com/en-us/azure/sentinel/migration-ingestion-tool
Migrate QRadar SOAR automation to Sentinel automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-automation
Migrate QRadar detection rules to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-detection-rules
Export QRadar historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-qradar-historical-data
Migrate Splunk SOAR automation to Sentinel automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-automation
Migrate Splunk detection rules to Microsoft Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-detection-rules
Export Splunk historical data for Sentinel migrationhttps://learn.microsoft.com/en-us/azure/sentinel/migration-splunk-historical-data
Choose between Sentinel standalone and XDR alert connectorshttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema-differences
Select Sentinel content hub solutions by domainhttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-catalog
Use Sentinel SIEM migration experience for rule mappinghttps://learn.microsoft.com/en-us/azure/sentinel/siem-migration
Apply SOC optimization recommendations in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-access

Architecture & Design Patterns

TopicURL
Design Sentinel SOAR with automation rules and playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/automation
Bring custom machine learning models into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/bring-your-own-ml
Design BCDR and resiliency architecture for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/business-continuity-disaster-recovery
Query and manage Sentinel data across workspaces and tenantshttps://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
Investigate Sentinel incidents using large dataset searchhttps://learn.microsoft.com/en-us/azure/sentinel/investigate-large-datasets
Work with Sentinel incidents across multiple workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/multiple-workspace-view
Use Jupyter notebooks for Sentinel threat huntinghttps://learn.microsoft.com/en-us/azure/sentinel/notebooks
Design Microsoft Sentinel solution components and patternshttps://learn.microsoft.com/en-us/azure/sentinel/partner-integrations
Design multi-workspace architecture for Sentinel SAPhttps://learn.microsoft.com/en-us/azure/sentinel/sap/cross-workspace
Use workspace manager to operate multiple Sentinel workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/workspace-manager

Limits & Quotas

TopicURL
Service limits and quotas for Microsoft Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-service-limits
Sentinel MCP server pricing, limits, and availabilityhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-billing
Select Microsoft Sentinel log retention tiers and limitshttps://learn.microsoft.com/en-us/azure/sentinel/log-plans
Review ASIM known issues and limitations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-known-issues
Understand removal impact of Microsoft Sentinel workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/offboard-implications
Run Sentinel search jobs for large datasets and archiveshttps://learn.microsoft.com/en-us/azure/sentinel/search-jobs
Review Microsoft Sentinel service limits and quotashttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-service-limits
Create Sentinel watchlists and manage file size limitshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-create

Security

TopicURL
Audit Microsoft Sentinel queries and user activitieshttps://learn.microsoft.com/en-us/azure/sentinel/audit-sentinel-data
Configure authentication for Microsoft Sentinel playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/authenticate-playbooks-to-sentinel
Define access restriction policies for Sentinel Standard playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/define-playbook-access-restrictions
Enable automated attack disruption actions on AWS identitieshttps://learn.microsoft.com/en-us/azure/sentinel/aws-disruption
Set up customer-managed keys for Microsoft Sentinel encryptionhttps://learn.microsoft.com/en-us/azure/sentinel/customer-managed-keys
Use audit log for Sentinel data lake and graph activitieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/auditing-lake-activities
Enable network security for Sentinel Azure Storage connectorhttps://learn.microsoft.com/en-us/azure/sentinel/enable-storage-network-security
Configure resource-context RBAC for Microsoft Sentinel data accesshttps://learn.microsoft.com/en-us/azure/sentinel/resource-context-rbac
Configure Microsoft Sentinel roles and permissionshttps://learn.microsoft.com/en-us/azure/sentinel/roles
ABAP roles and authorizations for Sentinel SAP logshttps://learn.microsoft.com/en-us/azure/sentinel/sap/required-abap-authorizations
SAP security parameters monitored by Sentinel analyticshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-suspicious-configuration-security-parameters
Configure row-level RBAC scoping in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/scoping

Configuration

TopicURL
Add advanced OR condition groups to Sentinel automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/add-advanced-conditions-to-automation-rules
Use Microsoft Sentinel audit tables for monitoringhttps://learn.microsoft.com/en-us/azure/sentinel/audit-table-reference
Configure Microsoft Sentinel automation rules and conditionshttps://learn.microsoft.com/en-us/azure/sentinel/automation-rule-reference
Security content reference for Power Platform and CEhttps://learn.microsoft.com/en-us/azure/sentinel/business-applications/power-platform-solution-security-content
Map CEF keys to Sentinel CommonSecurityLog fieldshttps://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping
Configure Syslog and CEF connectors via Azure Monitor Agenthttps://learn.microsoft.com/en-us/azure/sentinel/cef-syslog-ama-overview
Configure Security Events connector for anomalous RDP detectionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-connector-login-detection
Configure interactive and long-term Sentinel data retentionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-data-retention-archive
Configure ingestion-time data transformation and custom log ingestionhttps://learn.microsoft.com/en-us/azure/sentinel/configure-data-transformation
Configure Fusion multistage attack detection ruleshttps://learn.microsoft.com/en-us/azure/sentinel/configure-fusion-rules
Configure AWS service log connector for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws
Prepare AWS environment to send logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-configure-environment
Configure AWS WAF S3 connector to ingest logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-s3-waf
Configure Microsoft Entra ID connector to send logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-active-directory
Connect Azure Virtual Desktop telemetry to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-virtual-desktop
Configure Sentinel connections to Azure and Microsoft serviceshttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-windows-microsoft-services
Configure AMA-based syslog and CEF ingestion to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog-ama
Configure Custom Logs via AMA to ingest text-file logshttps://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs-ama
Connect Microsoft Defender for Cloud alerts to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-defender-for-cloud
Configure AMA connector for Windows DNS log streaminghttps://learn.microsoft.com/en-us/azure/sentinel/connect-dns-ama
Configure GCP Pub/Sub connectors to ingest logs into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-google-cloud-platform
Configure Microsoft Defender XDR connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender
Stream Microsoft Purview Information Protection data to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-purview
Configure API-based data connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-api-based
Configure diagnostic settings-based connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-diagnostic-setting-based
Configure Windows agent-based data connectors for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-services-windows-based
Create scheduled analytics rules from Sentinel templateshttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rule-from-template
Create custom scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rules
Configure incident creation from alerts in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts
Configure Sentinel automation rules for incident responsehttps://learn.microsoft.com/en-us/azure/sentinel/create-manage-use-automation-rules
Create and manage NRT detection rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-nrt-rules
Create Sentinel incident task lists via automation ruleshttps://learn.microsoft.com/en-us/azure/sentinel/create-tasks-automation-rule
Customize Sentinel alert names, severity, and tacticshttps://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details
Customize activities on Sentinel entity timelineshttps://learn.microsoft.com/en-us/azure/sentinel/customize-entity-activities
Configure CCF JSON for Azure Storage Blob connectorhttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-azure-storage
Configure RestApiPoller connector JSON for Sentinel CCFhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-connection-rules-reference
Reference Sentinel-supported data source schemashttps://learn.microsoft.com/en-us/azure/sentinel/data-source-schema-reference
Use asset data tables in Microsoft Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/asset-data-tables
Configure federated data connectors in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/data-federation-setup
Configure and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Configure and schedule KQL jobs in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-jobs
Manage Microsoft Sentinel data lake KQL jobshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-manage-jobs
Run and manage KQL queries in Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries
Create and schedule Sentinel Spark notebook jobshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-jobs
Configure connectors and retention for Sentinel data lake tiershttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-connectors
Onboard Sentinel data lake from Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboard-defender
Onboard tenants to Microsoft Sentinel data lake and graphhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-lake-onboarding
Configure data exploration tools in Sentinel MCP serverhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-data-exploration-tool
Configure and use Microsoft Sentinel MCP server toolshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-get-started
Use Sentinel MCP tools with Microsoft Foundry AI agentshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-azure-ai-foundry
Configure Sentinel MCP tools in Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-copilot-studio
Add Sentinel MCP tools to Microsoft Security Copilothttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-use-tool-security-copilot
Build Sentinel workbooks using data lake as sourcehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/workbooks-for-data-lake
Configure DNS over AMA connector fields and schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/dns-ama-fields
Security content reference for Dynamics 365 F&Ohttps://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/dynamics-365-finance-operations-security-content
Enable and configure Sentinel UEBA data sourceshttps://learn.microsoft.com/en-us/azure/sentinel/enable-entity-behavior-analytics
Enable Sentinel auditing and health monitoring and query logshttps://learn.microsoft.com/en-us/azure/sentinel/enable-monitoring
Use Sentinel entity types and identifiers correctlyhttps://learn.microsoft.com/en-us/azure/sentinel/entities-reference
Configure auditing and health monitoring in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/health-audit
Query and interpret Microsoft Sentinel health tableshttps://learn.microsoft.com/en-us/azure/sentinel/health-table-reference
Bulk import threat indicators from files into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/indicators-bulk-file-import
Manage Sentinel analytics rule template versionshttps://learn.microsoft.com/en-us/azure/sentinel/manage-analytics-rule-templates
Configure and manage installed Microsoft Sentinel platform solutionshttps://learn.microsoft.com/en-us/azure/sentinel/manage-platform-solutions
Configure table retention and tier settings for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/manage-table-tiers-retention
Map analytics rule fields to Sentinel entitieshttps://learn.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities
Use Purview Information Protection connector record types in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-purview-record-types-activities
Monitor Sentinel automation rules and playbook healthhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-automation-health
Monitor Microsoft Sentinel data connector health and ingestionhttps://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health
Monitor SAP–Sentinel connection health and alertshttps://learn.microsoft.com/en-us/azure/sentinel/monitor-sap-system-health
Configure multi-tenant management for Microsoft Sentinel MSSPshttps://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers
Configure near-real-time analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/near-real-time-rules
Manage workspace-deployed ASIM parsers in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-about-workspace-parsers
Apply ASIM common schema fields in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-common-fields
Develop and deploy custom ASIM parsers for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-develop-parsers
Implement ASIM Application Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-application
Implement ASIM Device Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-device
Implement ASIM User Entity schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-entity-user
Manage and customize ASIM parsers in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers
Convert Sentinel content to use ASIM normalized datahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-modify-content
Use ASIM Alert Events normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-alert
Use ASIM Audit Events normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-audit
Use ASIM Authentication normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-authentication
Use ASIM DHCP normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dhcp
Use ASIM DNS normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-dns
Use ASIM File Event normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-file-event
Use ASIM Network Session normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-network
Use ASIM Process Event normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-process-event
Use ASIM Registry Event normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-registry-event
Use Sentinel user management normalization schemahttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-user-management
Use legacy Sentinel network normalization schema v0.1https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-v1
Use ASIM Web Session normalization schema in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-web
Configure Sentinel notebooks and MSTICPy basicshttps://learn.microsoft.com/en-us/azure/sentinel/notebook-get-started
Apply advanced MSTICPy and notebook settings in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/notebooks-msticpy-advanced
Remove Microsoft Sentinel from a Log Analytics workspacehttps://learn.microsoft.com/en-us/azure/sentinel/offboard
Integrate Microsoft Purview solution with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/purview-solution
Restore archived Sentinel logs for high-performance querieshttps://learn.microsoft.com/en-us/azure/sentinel/restore
Configure SAP HANA audit log collection in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/collect-sap-hana-audit-logs
Prepare SAP systems for Sentinel SAP connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/preparing-sap
Review prerequisites for Sentinel SAP solution deploymenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/prerequisites-for-deploying-sap-continuous-threat-monitoring
Kickstart script parameters for SAP connector deploymenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-kickstart
Legacy systemconfig.ini settings for Sentinel SAP agenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-systemconfig
systemconfig.json settings for Sentinel SAP agenthttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-systemconfig-json
Update script parameters for Sentinel SAP connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/reference-update
Use SAP Security Audit Controls workbook in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-audit-controls-workbook
Use SAP Security Audit log workbook in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-audit-log-workbook
Security content reference for Sentinel SAP BTP solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-btp-security-content
Function reference for Sentinel SAP solution workspacehttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-function-reference
Log and table schema reference for Sentinel SAP solutionhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-log-reference
Reference for Sentinel SAP security content and ruleshttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-security-content
Stop SAP log collection and disable Sentinel connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/stop-collection
Configure scheduled analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/scheduled-rules-overview
Use Microsoft Sentinel security alert schemahttps://learn.microsoft.com/en-us/azure/sentinel/security-alert-schema
Map Sentinel tables to their data connectorshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-tables-connectors-reference
Use customizable anomaly detection in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/soc-ml-anomalies
Prepare prerequisites for Microsoft Sentinel SIEM solutionshttps://learn.microsoft.com/en-us/azure/sentinel/solution-setup-essentials
Configure and use summary rules to aggregate Sentinel datahttps://learn.microsoft.com/en-us/azure/sentinel/summary-rules
Surface custom event details in Sentinel alertshttps://learn.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts
Configure threat intelligence integrations in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/threat-intelligence-integration
Configure filter and split transformations in Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/transformation-filter-split
Reference for Sentinel UEBA entity enrichmentshttps://learn.microsoft.com/en-us/azure/sentinel/ueba-reference
Configure unified connectors to integrate with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/unified-connector-integration
Apply built-in Sentinel watchlist template schemashttps://learn.microsoft.com/en-us/azure/sentinel/watchlist-schemas
Select Windows security event sets for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/windows-security-event-id-reference
Create and tune anomaly analytics rules in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-anomaly-rules
Configure multiple Microsoft Sentinel workspaces in Defender portalhttps://learn.microsoft.com/en-us/azure/sentinel/workspaces-defender-portal

Integrations & Coding Patterns

TopicURL
Create Sentinel Data Collection Rules via API exampleshttps://learn.microsoft.com/en-us/azure/sentinel/api-dcr-reference
Use Sentinel Logic Apps triggers and actions in playbookshttps://learn.microsoft.com/en-us/azure/sentinel/automation/playbook-triggers-actions
Integrate Sentinel incidents with Microsoft Teams collaborationhttps://learn.microsoft.com/en-us/azure/sentinel/collaborate-in-microsoft-teams
Ingest AWS EKS audit logs into Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-aws-eks
Build Azure Functions-based connectors to ingest data into Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-functions-template
Use Logstash with DCR-based API to stream logs to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-logstash-data-connection-rules
Enable Defender Threat Intelligence data connector in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-mdti-data-connector
Connect STIX/TAXII threat intel feeds to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii
Connect threat intelligence platform to Sentinel (legacy connector)https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-tip
Connect TIP to Sentinel using Threat Intel upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api
Create codeless connectors for Microsoft Sentinel with CCFhttps://learn.microsoft.com/en-us/azure/sentinel/create-codeless-connector
Build push-based codeless connectors for Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/create-push-codeless-connector
Configure GCP data connectors with Sentinel CCFhttps://learn.microsoft.com/en-us/azure/sentinel/data-connection-rules-reference-gcp
Define connector UIConfig JSON for Sentinel CCFhttps://learn.microsoft.com/en-us/azure/sentinel/data-connector-ui-definitions-reference
Build and manage custom security graphs with Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/create-custom-graphs
Use GQL syntax to query Sentinel custom graphshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/gql-reference-for-sentinel-custom-graph
Call Sentinel custom graph REST APIs programmaticallyhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/graph-rest-api
Run Sentinel data lake KQL queries via REST APIshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/kql-queries-api
Notebook code examples for querying Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebook-examples
Use Jupyter notebooks with Sentinel data lake in VS Codehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/notebooks
Use Sentinel graph provider API in Spark notebookshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-graph-provider-reference
Leverage Sentinel MCP agent creation tool collectionhttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-agent-creation-tool
Enable and use Microsoft Sentinel MCP connector with ChatGPT or Claudehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-chatgpt-claude-connector
Create custom Sentinel MCP tools from KQL querieshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-create-custom-tool
Integrate Sentinel MCP tools into Azure Logic Appshttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-logic-apps
Use Sentinel MCP triage tools for incident huntinghttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-mcp-triage-tool
Use SentinelProvider class to access Sentinel data lakehttps://learn.microsoft.com/en-us/azure/sentinel/datalake/sentinel-provider-class-reference
Enrich Sentinel entities with geolocation REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/geolocation-data-api
Manage Microsoft Sentinel hunting queries via REST APIhttps://learn.microsoft.com/en-us/azure/sentinel/hunting-with-rest-api
Author custom hunting KQL queries in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/hunts-custom-queries
Ingest Defender for Cloud incidents via Defender XDRhttps://learn.microsoft.com/en-us/azure/sentinel/ingest-defender-for-cloud-incidents
Integrate Microsoft Defender XDR with Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration
Use ASIM helper functions for normalized data in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/normalization-functions
Build Power BI reports from Sentinel log datahttps://learn.microsoft.com/en-us/azure/sentinel/powerbi
Trigger Sentinel playbooks from entities during huntshttps://learn.microsoft.com/en-us/azure/sentinel/respond-threats-during-investigation
Create analytics rules for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-analytic-rules-creation
Create hunting queries for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-hunting-rules-creation
Build and publish Microsoft Sentinel SIEM solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-integration-guide
Create and publish playbooks for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-playbook-creation
Create summary rules and tables for Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-summary-rules-creation
Create and publish workbooks for Microsoft Sentinel solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-workbook-creation
Configure Azure Storage Blob connector for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/setup-azure-storage-connector
Call Microsoft Sentinel SOC optimization recommendations APIhttps://learn.microsoft.com/en-us/azure/sentinel/soc-optimization/soc-optimization-api
Import threat intelligence using Sentinel STIX upload APIhttps://learn.microsoft.com/en-us/azure/sentinel/stix-objects-api
Enrich Sentinel incidents with IP reputation automationhttps://learn.microsoft.com/en-us/azure/sentinel/tutorial-enrich-ip-information
Extract non-native Sentinel entities using playbook actionshttps://learn.microsoft.com/en-us/azure/sentinel/tutorial-extract-incident-entities
Use legacy Sentinel upload indicators APIhttps://learn.microsoft.com/en-us/azure/sentinel/upload-indicators-api
Use Sentinel watchlists in KQL queries and ruleshttps://learn.microsoft.com/en-us/azure/sentinel/watchlists-queries
Query STIX indicator and object tables in Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/work-with-stix-objects-indicators

Deployment

TopicURL
Deploy Sentinel solution for Power Platform and CEhttps://learn.microsoft.com/en-us/azure/sentinel/business-applications/deploy-power-platform-solution
Create repository connections to deploy Sentinel contenthttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd
Use repositories and CI/CD for Microsoft Sentinel contenthttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-content
Customize CI/CD repository deployments for Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-deploy
Onboard Azure Stack Hub VMs to Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/connect-azure-stack
Deploy Sentinel solution for Dynamics 365 Finance and Operationshttps://learn.microsoft.com/en-us/azure/sentinel/dynamics-365/deploy-dynamics-365-finance-operations-solution
Import and export Sentinel analytics rules via ARMhttps://learn.microsoft.com/en-us/azure/sentinel/import-export-analytics-rules
Manage Sentinel automation rules as code with ARM templateshttps://learn.microsoft.com/en-us/azure/sentinel/import-export-automation-rules
Check Sentinel Defender XDR data support by cloudhttps://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-cloud-support
Run Sentinel hunting notebooks in Azure ML workspaceshttps://learn.microsoft.com/en-us/azure/sentinel/notebooks-hunt
Package and publish Microsoft Sentinel platform solutionshttps://learn.microsoft.com/en-us/azure/sentinel/package-platform-solution
Publish Microsoft Sentinel SIEM solutions to marketplacehttps://learn.microsoft.com/en-us/azure/sentinel/publish-sentinel-solutions
Deploy SAP connector container via command linehttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-command-line
Deploy SAP data connector container to Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-data-connector-agent-container
Deploy Sentinel solution for SAP BTP systemshttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-sap-btp-solution
Install Microsoft Sentinel solution for SAP applicationshttps://learn.microsoft.com/en-us/azure/sentinel/sap/deploy-sap-security-content
Migrate Sentinel SAP container agent to agentless connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-agent-migrate
Expert deployment options for Sentinel SAP connectorhttps://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-deploy-alternate
Update Sentinel SAP data connector agent safelyhttps://learn.microsoft.com/en-us/azure/sentinel/sap/update-sap-data-connector
Discover and deploy Sentinel content hub solutionshttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-deploy
Track Microsoft Sentinel solution status after publishinghttps://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-post-publish-tracking

适合场景

01

Azure 资源规划

02

云服务升级

03

基础设施检查

04

企业云环境自动化

能力概览

能力 1

整理 Azure 服务操作流程

能力 2

提示 CLI/MCP 前置条件

能力 3

辅助云资源检查和规划

能力 4

保留官方服务来源线索

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.31%
按下载量换算103

Claude

32.39%
按下载量换算100

Cursor

19.87%
按下载量换算61

Gemini CLI

9.77%
按下载量换算30

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills