After deploying Sentinel by creating/assigning a Log Analytics Workspace, next phase is to ingest logs in to Log Analytics Workspaces using data connectors. Data connectors are used to get logs from various sources. This includes the cloud native sources as well as third party sources.
Microsoft Sentinel Content hub enables you to discover and install out of the box solutions for Sentinel. This solution is like a package that includes analytics rules, data connectors, playbooks etc pertaining to that particular product or solution. So, when a solution is deployed from the content hub, these associated components will also get installed. If the entire contents are not required then we can opt for a stand-alone content source.
Microsoft Sentinel Content hub enables you to discover and install out of the box solutions for Sentinel. This solution is like a package that includes analytics rules, data connectors, playbooks etc pertaining to that particular product or solution. So, when a solution is deployed from the content hub, these associated components will also get installed. If the entire contents are not required then we can opt for a stand-alone content source.
Lets install Microsoft Entra ID solution from Content hub.
Click on Install.
We can see, there are 64 analytics rules, 1 data connector, 11 playbooks and 2 workbooks in this solution. Click on Manage to configure.
We can click on each content and configure separately.