10: Content Hub Flashcards
(12 cards)
What is the Content Hub in Sentinel?
It’s a central library where you can find and install solution packages that include prebuilt content like connectors, analytics rules, hunting queries, workbooks, playbooks, and parsers.
What is a solution in the Content Hub?
A solution is a bundled set of content tailored to a specific product, vendor, or threat scenario. It might include a data connector, detections, visualizations, and automation—all prebuilt and ready to deploy.
What kind of content can a solution include?
Data connectors, analytics rules, hunting queries, workbooks, playbooks, and parsers.
What’s the benefit of using solutions from the Content Hub?
You save time by deploying curated, tested content designed for specific tools or threats. It jumpstarts your deployment and detection coverage.
Can you customize the content in a solution after installing it?
Yes. All content from a solution—like rules, queries, and workbooks—can be edited or cloned after installation.
Where does solution content show up once installed?
In their respective areas: connectors go under Data Connectors, rules under Analytics, workbooks under Workbooks, etc.
Why is the Content Hub useful for customers with limited time or expertise?
It gives them a head start with ready-made content that’s tailored to their tools, reducing the need to build detections and dashboards from scratch.
How often is Content Hub content updated?
Microsoft and partners regularly publish updates, and Sentinel flags solutions with available updates in the Content Hub.
Do I need to install the whole solution, or can I pick just one part?
You install the whole solution, but you can choose which content to enable or customize afterward.
Can I see what’s in a solution before installing it?
Yes. Each solution listing includes a description and a list of included components like rules, workbooks, and connectors.
Is installing a solution reversible?
Not with a single button, but you can manually delete any installed content you don’t want.
Can I create my own solution to share across tenants?
Not directly through Content Hub yet, but you can export custom content and share it via ARM templates or GitHub.