Australia

Microsoft Sentinel onboarding, in Sentinel's own vocabulary.

Data connectors, AMA and DCRs, analytics rules, Log Analytics workspace design and KQL: the full Sentinel onboarding pack, with IRAP-assessed hosting flagged where government work constrains platform choice.

What a Sentinel pack contains

Source runbooks per data connector, workspace and table design notes, analytics rule priorities per sector, validation steps for each connected source, and a go-live checklist covering ingestion health and cost controls.

Where CrowdStrike or Splunk fits

Australian estates that already run Falcon EDR often extend into CrowdStrike's SIEM; Splunk remains strong in larger environments. Blueprint documents both in their own terminology, so the pack matches the platform your team actually operates.

Microsoft Sentinel

Data connector
Azure Monitor Agent with Data Collection Rules
ASIM and Log Analytics table schemas
Analytics rule
Incident
Log Analytics workspace
Automation rules and Logic Apps playbooks
  • Prerequisites confirmed, credentials and permissions granted via secure channel
  • Data connector enabled, connector status shows Connected in the Sentinel portal
  • 24-hour continuous ingestion confirmed, no unexplained gaps in the workspace
  • Table population verified by KQL query against the expected table, for example SigninLogs
  • Data Collection Rule scope confirmed correct for the intended hosts
  • Timestamp accuracy, TimeGenerated against event time within tolerance
  • Test event confirmed, controlled action returned by KQL query within 5 minutes
  • Named source owner sign-off

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in Australia.

Apply as a partner