How to get Azure Security center recommandations into Sentinel?

Mohammad Hasan 1 Reputation point
2021-05-03T04:52:11.987+00:00

In my organization we have Azure security center and Azure Sentinel in same Workspace and they are connected. But need to know how we can list/query all the recommendations of Security center in sentinel.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,186 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
971 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Yash Mudaliar 191 Reputation points Microsoft Employee
    2021-05-03T15:24:50.83+00:00

    Hi @Mohammad Hasan ,

    For exporting all the recommendation (and alerts if you need) from the Security Center to Sentinel, you need to enable 'Continuous Export' from Azure Security Center.
    For that, follow the below path:

    In Security Center go to Pricing and Settings -> Select your subscription -> Continuous Export -> Select 'Log Analytics Workspace' tab and switch the toggle to 'ON'.
    You can select the checkboxes of the items you want to export. Example attached.

    If this answer helps you, please accept it as an answer and upvote it.93343-screenshot-2021-05-03-162326.png

    0 comments No comments

  2. Mohammad Hasan 1 Reputation point
    2021-05-04T05:00:03.78+00:00

    @Yash Mudaliar Thanks for the feedback. i have done that. But 'Continuous Export' only does export new recommendations into Sentinel or log analytics workspace.

    What is the way to export all the existing Security center recommendations into Sentinel? is there any way to sync?

    0 comments No comments

  3. Saurabh Sharma 23,671 Reputation points Microsoft Employee
    2021-05-20T22:56:21.45+00:00

    Hi @Mohammad Hasan ,

    This is unfortunately not possible as recommendations are sent whenever a resource's compliance state changes so it will be sent to your Sentinel or Log Analytics workspace before the enablement.

    Please refer to the documentation.
    Also, please provide this as a feedback at Azure Security Center Uservoice.

    Thanks
    Saurabh

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    0 comments No comments