{
"cells": [
{
"cell_type": "markdown",
"metadata": {},
"source": [
"# Notebook Title\n",
" Details...
\n",
"\n",
" **Notebook Version:** 1.0
\n",
" **Python Version:** Python 3.6 (including Python 3.6 - AzureML)
\n",
" **Required Packages**: kqlmagic, msticpy, pandas, pandas_bokeh, numpy, matplotlib, networkx, seaborn, datetime, ipywidgets, ipython, dnspython, ipwhois, folium, maxminddb_geolite2
\n",
" **Platforms Supported**:\n",
" - Azure Notebooks Free Compute\n",
" - Azure Notebooks DSVM\n",
" - OS Independent\n",
"\n",
" **Data Sources Required**:\n",
" - Log Analytics/Azure Sentinel - Syslog, Secuirty Alerts, Auditd, Azure Network Analytics.\n",
" - (Optional) - AlienVault OTX (requires account and API key)\n",
"
\n", "connect_str = \"loganalytics://tenant(TENANT_ID).workspace(WORKSPACE_ID).clientid(client_id).clientsecret(client_secret)\"\n", "qry_prov.connect(connect_str)\n", "\n", "instead of
\n", "qry_prov.connect(ws_config)\n", "\n", "\n", "To find your Workspace Id go to\n", "[Azure Sentinel Workspaces](https://ms.portal.azure.com/#blade/HubsExtension/Resources/resourceType/Microsoft.OperationalInsights%2Fworkspaces).\n", "Look at the workspace properties to find the ID.\n", "