8.1 Security Information and Event Management8.2 Microsoft Sentinel8.2.1 Microsoft Sentinel capabilities8.2.2 Enabling Microsoft Sentinel8.3 Data collection8.3.1 What data should go in a SIEM?8.3.2 Data connectors8.3.3 Data connectors in action8.3.4 Content hub8.4 Analytics rules8.4.1 Microsoft security rules8.4.2 Microsoft security rules in action8.4.3 Scheduled rules8.4.4 Scheduled rules in action8.5 Incidents8.6 User and entity behavior analytics8.6.1 When to use UEBA8.6.2 User and entity behavior analytics in action8.7 Security orchestration, automation, and response8.8 Automation rules8.8.1 Automation elements and trigger events8.8.2 Automation rules in action8.9 Answers to ExercisesExercise 8.1Exercise 8.2Exercise 8.3Summary