NO Indcidents or Alerts generated in Sentinel/Defender Portal

Haskee 0 Reputation points
2025-12-28T04:02:32.52+00:00

Hi!,

I am tryign to learn Azure eco system. I spinned up 2 VM's one Windows Server and other as Linux machine. Setup Log anlytics and all connected and can see logs from VM's. However when installed senintel , also connected with data connecotrs & I can see logs . Rule templates also enabled for lsass , however when i generated telemetry data using Atomic red team use cases no detection triggered into sentintel/defender portal. Not sure whats an issue still cant figure out. Any help appreciated . Thanks

Microsoft Security | Microsoft Defender | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2025-12-28T04:02:41.3466667+00:00

    It seems like you're experiencing issues with alerts and incidents not being generated in Microsoft Sentinel despite having set up your environment correctly. Here are a few things to check:

    1. Rule Configuration: Ensure that the analytics rules you have enabled are properly configured to detect the specific telemetry data generated by the Atomic Red Team use cases. Sometimes, the rules may not be set to trigger on the specific events you are generating.
    2. Data Connectors: Verify that all necessary data connectors are properly configured and connected. If the data connectors are not set up correctly, Sentinel may not receive the required telemetry data to trigger alerts.
    3. Log Analytics Workspace: Confirm that your Log Analytics workspace is correctly linked to your Sentinel instance. You should be able to see the logs in both places.
    4. Testing with Known Threats: Sometimes, using known threat scenarios or test alerts can help in validating whether the detection mechanisms are working. Ensure that the telemetry data you are generating is recognized by the rules you have set up.
    5. Review Logs: Check the logs in the Log Analytics workspace for any errors or warnings that might indicate why alerts are not being generated. This can provide insights into any misconfigurations or issues.
    6. Consult Documentation: Refer to the official Microsoft documentation for guidance on creating and managing analytics rules and alerts in Sentinel. This can help you ensure that you are following best practices.

    If after checking these points you still face issues, consider reaching out to Microsoft support or community forums for more specific troubleshooting assistance.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.