Microsoft Sentinel is enabled on top of the Log Analytics workspace. The workspace stores the data, and Microsoft Sentinel provides security analytics, investigation, workbooks, incidents, and automation.
In the Azure portal, search for Microsoft Sentinel.
In the Microsoft Sentinel page, click Create or Add.