azure-sentinel

Troubleshoot and optimize Azure Sentinel deployments with KQL and connector guidance.

686|107|Updated Jan 27, 2026
One-click install
npx skills add https://github.com/MicrosoftDocs/Agent-Skills --skill azure-sentinel-microsoftdocs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: azure-sentinel
Source: https://github.com/MicrosoftDocs/Agent-Skills/tree/main/skills/azure-sentinel
Command: npx skills add https://github.com/MicrosoftDocs/Agent-Skills --skill azure-sentinel-microsoftdocs

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides comprehensive expertise for Azure Sentinel, enabling users to effectively build, debug, and optimize security operations within the Azure cloud environment.

Core Features & Use Cases

  • Troubleshooting: Diagnose and resolve issues with data ingestion, connectors, KQL queries, and more.
  • Best Practices: Implement optimal strategies for SOC operations, rule tuning, automation, and incident management.
  • Architecture & Design: Design secure and efficient Sentinel deployments, including multi-workspace and MSSP scenarios.
  • Use Case: A security analyst is struggling to ingest logs from an AWS S3 bucket into Azure Sentinel. They can use this Skill to find troubleshooting steps and best practices for the AWS S3 connector.

Quick Start

Use the azure-sentinel skill to find troubleshooting steps for the AWS S3 connector.

Frequently Asked Questions about azure-sentinel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I troubleshoot data ingestion issues with Azure Sentinel connectors?

To troubleshoot Azure Sentinel data ingestion, use this Skill to diagnose connector issues, fetch remote documentation, and apply best practices for resolving log ingestion failures.

What is the best way to design a multi-workspace Azure Sentinel architecture?

Designing a multi-workspace Azure Sentinel architecture involves applying best practices for secure deployments, including MSSP scenarios, to ensure efficient security operations and centralized threat detection.

How do I optimize KQL queries for threat detection in Azure Sentinel?

Optimize KQL queries for threat detection in Azure Sentinel by leveraging expert knowledge on rule tuning, debugging, and security operations best practices provided by this Skill.

Does Azure Sentinel require specific tools for documentation retrieval during configuration?

Azure Sentinel configuration requires network access and specific tools like mcp_microsoftdocs or fetch_webpage to retrieve remote documentation for building and optimizing security applications.

Why is my AWS S3 connector not ingesting logs into Azure Sentinel?

If your AWS S3 connector is not ingesting logs into Azure Sentinel, use this Skill to find specific troubleshooting steps, diagnose configuration issues, and implement recommended best practices.