Skip to main content

Scenarios

Synopsis​

Scenarios is a course of guided data flows, each built around a Content Hub pack and taught on the real screens. A scenario follows one flow end to end, from the device that sends the logs to the SIEM that receives them, one part at a time.

The course asks which SIEM you send to first. Each SIEM then has the same four scenarios, built on its own Automation and Normalization Pack.

Scenarios is one of the courses in the Guided tours panel, beside the Getting started tours described in Onboarding and the Pipeline Academy.

Opening Scenarios​

Three ways lead to the Scenarios:

  • Onboarding page: the Or start from a real scenario section, with a card for each scenario (see Scenario Cards). See all scenarios opens the Guided tours panel on the Scenarios tab.
  • Content Hub: Scenarios, at the end of the page's title row (see Content Hub). It opens the Guided tours panel on the Scenarios tab.
  • Help menu: select the ? in the header, then Guided tours, then the Scenarios tab, after Getting started and Pipeline Academy.

Choosing Your SIEM​

Both the Scenarios tab and the onboarding section open with the question Which SIEM do you send to?, answered with one of three tiles:

TileLine under it
Microsoft SentinelScenarios on the Microsoft Sentinel Automation and Normalization Pack.
Splunk Enterprise SecurityScenarios on the Splunk Enterprise Security Automation and Normalization Pack.
Elastic SecurityScenarios on the Elastic Security Automation and Normalization Pack.

Until you answer, neither place lists any scenario or shows progress.

Your answer is saved per user, like your progress. The onboarding page and the Guided tours panel always show the same answer, and you can change it at any time by picking another tile.

If you finished Sentinel parts before the course asked for a SIEM, you are shown the Sentinel scenarios without being asked.

The Scenarios Tab​

The tab opens with a short description of the course and a progress line, n of 12 parts completed, counting the chosen SIEM's parts. Each scenario follows, headed Scenario 1 to Scenario 4, with its title, description, and flow. Its parts are numbered Part 1, Part 2, and so on within that scenario.

Scenario Cards​

On the Onboarding page, the Or start from a real scenario section sits between the guided setup card and the setup steps. It reads "Pick the flow that matches yours, from the device to the destination, and follow it on the real screens, one part at a time." It asks for your SIEM first, then shows one card per scenario. Each card shows:

  • the scenario's flow, as stops joined by arrows, for example FortiGate, CEF → Syslog on UDP 514 → Sentinel pack → Microsoft Sentinel
  • its title and a one-line description
  • its length, such as 5 parts · about 27 min, or its progress once started, such as 3 of 5 parts done

The card's button is Start scenario, or Continue once a part is done. It starts the first part not yet done. A finished scenario shows Completed and no button. When the parts left need a permission your role lacks, the card reads "Your role does not include this. Ask an administrator for access." in place of the button.

Scenarios and Parts​

Each SIEM has the same four scenarios, built on its own pack.

Microsoft Sentinel​

ScenarioParts, in order
FortiGate CEF logs to Microsoft SentinelReceive FortiGate logs over UDP · Connect Microsoft Sentinel · Install the Sentinel pack and deploy its route · See what a FortiGate line becomes · Choose CommonSecurityLog or ASIM
Palo Alto logs to Microsoft Sentinel, recognised by autodiscoveryReceive Palo Alto logs over UDP · How autodiscovery recognises a vendor · Connect Microsoft Sentinel · Install the Sentinel pack and deploy its route · Add vendors to an installed Sentinel pack · See what a PAN-OS line becomes · Choose CommonSecurityLog or ASIM
Send less to Microsoft SentinelInstall the Sentinel pack and deploy its route · Send less to Sentinel
Keep a raw copy in Azure Blob StorageInstall the Sentinel pack and deploy its route · Connect Azure Blob Storage · Send a raw copy to Blob

Splunk Enterprise Security​

ScenarioParts, in order
FortiGate CEF logs to Splunk Enterprise SecurityReceive FortiGate logs over UDP · Connect Splunk Enterprise Security · Install the Splunk ES pack and deploy its route · See what a FortiGate line becomes · See what lands where in Splunk
Palo Alto logs to Splunk Enterprise Security, recognised by autodiscoveryReceive Palo Alto logs over UDP · How autodiscovery recognises a vendor · Connect Splunk Enterprise Security · Install the Splunk ES pack and deploy its route · Add vendors to an installed Splunk ES pack · See what a PAN-OS line becomes · See what lands where in Splunk
Send less to SplunkInstall the Splunk ES pack and deploy its route · Send less to Splunk
Keep a raw copy in Azure Blob StorageInstall the Splunk ES pack and deploy its route · Connect Azure Blob Storage · Send a raw copy to Blob

Elastic Security​

ScenarioParts, in order
FortiGate CEF logs to Elastic SecurityReceive FortiGate logs over UDP · Connect Elastic Security · Install the Elastic Security pack and deploy its route · See what a FortiGate line becomes · See what lands where in Elastic
Palo Alto logs to Elastic Security, recognised by autodiscoveryReceive Palo Alto logs over UDP · How autodiscovery recognises a vendor · Connect Elastic Security · Install the Elastic Security pack and deploy its route · Add vendors to an installed Elastic Security pack · See what a PAN-OS line becomes · See what lands where in Elastic
Send less to ElasticInstall the Elastic Security pack and deploy its route · Send less to Elastic
Keep a raw copy in Azure Blob StorageInstall the Elastic Security pack and deploy its route · Connect Azure Blob Storage · Send a raw copy to Blob

Shared Parts​

A part that appears in more than one scenario is one part: done once, it counts as done in every scenario that lists it. That is why each SIEM's course counts 12 parts.

  • Within a SIEM: its target (for example Connect Microsoft Sentinel), its pack (Install the … pack and deploy its route), and, for Sentinel, Choose CommonSecurityLog or ASIM and for Splunk and Elastic, See what lands where in ….
  • Across all three SIEMs: Receive FortiGate logs over UDP, Receive Palo Alto logs over UDP, How autodiscovery recognises a vendor, See what a FortiGate line becomes, See what a PAN-OS line becomes, and Connect Azure Blob Storage. Done once, they count as done under whichever SIEM you choose later.

What the Packs Do​

The route parts teach how each SIEM's pack splits the data:

  • Microsoft Sentinel: Choose CommonSecurityLog or ASIM picks which tables Sentinel keeps the events in.
  • Splunk Enterprise Security and Elastic Security: the security app receives only the events that map to an ASIM table, normalized as CIM (Splunk) or ECS (Elastic). Everything else goes to the logs-csl stream or index on a plain Splunk or Elasticsearch copy.
    • Splunk ES: a stream name picks an HTTP Event Collector endpoint by the ?logs-… suffix on its URL, and the index is the target's own.
    • Elastic Security: the route names the index (logs-networksession and so on), and the target's own index takes only events that arrive without one.
  • Send less: the optimization switches trim only the plain Splunk or Elasticsearch copy, never the security app's events.
  • Raw copy: all three SIEMs keep the raw copy in Azure Blob Storage, through the pack's object-storage slot: use_azblob / target_for_azblob on the Sentinel pack, use_object_storage / target_for_object_storage on the Splunk ES and Elastic Security packs. Neither the Splunk ES nor the Elastic Security pack has an S3 slot.

The route configuration keys the parts change, such as the table choice, the optimization switches (use_event_filters, use_sampling, sample_rate, use_asim_filters), and the Blob copy, are described in Content Routing: Advanced Configuration. The target settings the parts fill in are described in Microsoft Sentinel, Splunk Enterprise Security (endpoints, token, index, source_type), Elastic Security (endpoints, username, password, index), and Azure Blob Storage.

Who Can Take Which Part​

Each part checks its permissions before it offers Start, and a part your role cannot take shows no Start button.

PermissionParts
Device createReceive FortiGate logs over UDP, Receive Palo Alto logs over UDP
Target createConnect Microsoft Sentinel, Connect Splunk Enterprise Security, Connect Elastic Security, Connect Azure Blob Storage
Pipeline create and Advanced route createInstall the … pack and deploy its route, for each SIEM
Pipeline createAdd vendors to an installed … pack, for each SIEM
Advanced route editChoose CommonSecurityLog or ASIM, See what lands where in Splunk, See what lands where in Elastic, the three Send less to … parts, and the three Send a raw copy to Blob parts
Content Hub readHow autodiscovery recognises a vendor, See what a FortiGate line becomes, See what a PAN-OS line becomes

What the Parts Change​

warning

The parts run in your own organization, not in a sandbox, and create and change real items.

Taken on a tenant, the parts:

  • create a Syslog device
  • create a target for the chosen SIEM (Microsoft Sentinel, Splunk Enterprise Security, or Elastic Security) and an Azure Blob Storage target
  • install the SIEM's Automation and Normalization Pack with its advanced route, plus optional vendor packs (Fortinet FortiGate Pack; Syslog Vendor Autodiscovery Pack and Palo Alto Networks PAN-OS Pack)
  • edit that route's configuration

The route parts open the route from the pack's page, through Actions → See installed route, not from the Advanced Routes list, so you always edit the route that pack installed.

Progress​

Completed parts are saved per user, as for the other courses.