Step 3: Enabling Microsoft Sentinel

Microsoft Sentinel is enabled on top of the Log Analytics workspace. The workspace stores the data, and Microsoft Sentinel provides security analytics, investigation, workbooks, incidents, and automation.

  1. In the Azure portal, search for Microsoft Sentinel.
  2. In the Microsoft Sentinel page, click Create or Add.
  3. In the Add Microsoft Sentinel to a workspace page that appears, select the Log Analytics workspace created in Step 2: Creating a Log Analytics Workspace.

  4. Select Add.

    Wait for the onboarding process to complete.

    Note:

    Enabling Sentinel does not start sending Avanan events. The event ingestion connection is configured from the Step 4: Installing the Avanan Solution.