Challenge 01 - Architecture, Agents, Data Connectors and Workbooks </br>

Home - Next Challenge>

Introduction

In this challenge you will decide on an architecture for your Sentinel workspace(s) and what information will be stored in that Log Analytics workspace. Then you will add Sentinel to that workspace and confirm you can now access Sentinel. Next, you will deploy agents to get data into the log analytics workspace.

Description

This is a net new install, you need to design the workspace environment to meet the following requirements. Create a short doc that describes your decision and justification for these requirements:

Tasks - Instanciate Your Microsoft Sentinel Environment

Success Criteria

To complete this challenge you need to design and deploy an architecture and install an agent on the two windows machines.

Learning Resources

The following articles will help you decide on an architecture, explain the alternatives and decide on the data connector required.

Tips

Don’t overthink the architecture, the guide here is to get you to understand the options. Ask yourself why would I need multiple Sentinel workspaces, and what is the impact of doing so? For the workbook, don’t create one, use an existing workbook.

Advanced Challenges

Too comfortable? Eager to do more? Try these additional challenges!