Scenarios
Synopsis
Scenarios is a course of guided data flows, each built around a Content Hub pack and taught on the real screens. A scenario follows one flow end to end, from the device that sends the logs to the SIEM that receives them, one part at a time.
The course asks which SIEM you send to first. Each SIEM then has the same four scenarios, built on its own Automation and Normalization Pack.
Scenarios is one of the courses in the
Opening Scenarios
Three ways lead to the Scenarios:
- Onboarding page: the Or start from a real scenario section, with a card for each scenario (see Scenario Cards).
See all scenarios opens theGuided tours panel on the Scenarios tab. - Content Hub:
Scenarios , at the end of the page's title row (see Content Hub). It opens theGuided tours panel on the Scenarios tab. - Help menu: select the
? in the header, thenGuided tours , then the Scenarios tab, after Getting started and Pipeline Academy.
Choosing Your SIEM
Both the Scenarios tab and the onboarding section open with the question Which SIEM do you send to?, answered with one of three tiles:
| Tile | Line under it |
|---|---|
| Microsoft Sentinel | Scenarios on the Microsoft Sentinel Automation and Normalization Pack. |
| Splunk Enterprise Security | Scenarios on the Splunk Enterprise Security Automation and Normalization Pack. |
| Elastic Security | Scenarios on the Elastic Security Automation and Normalization Pack. |
Until you answer, neither place lists any scenario or shows progress.
Your answer is saved per user, like your progress. The onboarding page and the
If you finished Sentinel parts before the course asked for a SIEM, you are shown the Sentinel scenarios without being asked.
The Scenarios Tab
The tab opens with a short description of the course and a progress line, n of 12 parts completed, counting the chosen SIEM's parts. Each scenario follows, headed Scenario 1 to Scenario 4, with its title, description, and flow. Its parts are numbered Part 1, Part 2, and so on within that scenario.
Scenario Cards
On the Onboarding page, the Or start from a real scenario section sits between the guided setup card and the setup steps. It reads "Pick the flow that matches yours, from the device to the destination, and follow it on the real screens, one part at a time." It asks for your SIEM first, then shows one card per scenario. Each card shows:
- the scenario's flow, as stops joined by arrows, for example FortiGate, CEF → Syslog on UDP 514 → Sentinel pack → Microsoft Sentinel
- its title and a one-line description
- its length, such as 5 parts · about 27 min, or its progress once started, such as 3 of 5 parts done
The card's button is
Scenarios and Parts
Each SIEM has the same four scenarios, built on its own pack.
Microsoft Sentinel
| Scenario | Parts, in order |
|---|---|
| FortiGate CEF logs to Microsoft Sentinel | Receive FortiGate logs over UDP · Connect Microsoft Sentinel · Install the Sentinel pack and deploy its route · See what a FortiGate line becomes · Choose CommonSecurityLog or ASIM |
| Palo Alto logs to Microsoft Sentinel, recognised by autodiscovery | Receive Palo Alto logs over UDP · How autodiscovery recognises a vendor · Connect Microsoft Sentinel · Install the Sentinel pack and deploy its route · Add vendors to an installed Sentinel pack · See what a PAN-OS line becomes · Choose CommonSecurityLog or ASIM |
| Send less to Microsoft Sentinel | Install the Sentinel pack and deploy its route · Send less to Sentinel |
| Keep a raw copy in Azure Blob Storage | Install the Sentinel pack and deploy its route · Connect Azure Blob Storage · Send a raw copy to Blob |
Splunk Enterprise Security
| Scenario | Parts, in order |
|---|---|
| FortiGate CEF logs to Splunk Enterprise Security | Receive FortiGate logs over UDP · Connect Splunk Enterprise Security · Install the Splunk ES pack and deploy its route · See what a FortiGate line becomes · See what lands where in Splunk |
| Palo Alto logs to Splunk Enterprise Security, recognised by autodiscovery | Receive Palo Alto logs over UDP · How autodiscovery recognises a vendor · Connect Splunk Enterprise Security · Install the Splunk ES pack and deploy its route · Add vendors to an installed Splunk ES pack · See what a PAN-OS line becomes · See what lands where in Splunk |
| Send less to Splunk | Install the Splunk ES pack and deploy its route · Send less to Splunk |
| Keep a raw copy in Azure Blob Storage | Install the Splunk ES pack and deploy its route · Connect Azure Blob Storage · Send a raw copy to Blob |
Elastic Security
| Scenario | Parts, in order |
|---|---|
| FortiGate CEF logs to Elastic Security | Receive FortiGate logs over UDP · Connect Elastic Security · Install the Elastic Security pack and deploy its route · See what a FortiGate line becomes · See what lands where in Elastic |
| Palo Alto logs to Elastic Security, recognised by autodiscovery | Receive Palo Alto logs over UDP · How autodiscovery recognises a vendor · Connect Elastic Security · Install the Elastic Security pack and deploy its route · Add vendors to an installed Elastic Security pack · See what a PAN-OS line becomes · See what lands where in Elastic |
| Send less to Elastic | Install the Elastic Security pack and deploy its route · Send less to Elastic |
| Keep a raw copy in Azure Blob Storage | Install the Elastic Security pack and deploy its route · Connect Azure Blob Storage · Send a raw copy to Blob |
Shared Parts
A part that appears in more than one scenario is one part: done once, it counts as done in every scenario that lists it. That is why each SIEM's course counts 12 parts.
- Within a SIEM: its target (for example Connect Microsoft Sentinel), its pack (Install the … pack and deploy its route), and, for Sentinel, Choose CommonSecurityLog or ASIM and for Splunk and Elastic, See what lands where in ….
- Across all three SIEMs: Receive FortiGate logs over UDP, Receive Palo Alto logs over UDP, How autodiscovery recognises a vendor, See what a FortiGate line becomes, See what a PAN-OS line becomes, and Connect Azure Blob Storage. Done once, they count as done under whichever SIEM you choose later.
What the Packs Do
The route parts teach how each SIEM's pack splits the data:
- Microsoft Sentinel: Choose CommonSecurityLog or ASIM picks which tables Sentinel keeps the events in.
- Splunk Enterprise Security and Elastic Security: the security app receives only the events that map to an ASIM table, normalized as CIM (Splunk) or ECS (Elastic). Everything else goes to the
logs-cslstream or index on a plain Splunk or Elasticsearch copy.- Splunk ES: a stream name picks an HTTP Event Collector endpoint by the
?logs-…suffix on its URL, and the index is the target's own. - Elastic Security: the route names the index (
logs-networksessionand so on), and the target's own index takes only events that arrive without one.
- Splunk ES: a stream name picks an HTTP Event Collector endpoint by the
- Send less: the optimization switches trim only the plain Splunk or Elasticsearch copy, never the security app's events.
- Raw copy: all three SIEMs keep the raw copy in Azure Blob Storage, through the pack's object-storage slot:
use_azblob/target_for_azblobon the Sentinel pack,use_object_storage/target_for_object_storageon the Splunk ES and Elastic Security packs. Neither the Splunk ES nor the Elastic Security pack has an S3 slot.
The route configuration keys the parts change, such as the table choice, the optimization switches (use_event_filters, use_sampling, sample_rate, use_asim_filters), and the Blob copy, are described in Content Routing: Advanced Configuration. The target settings the parts fill in are described in Microsoft Sentinel, Splunk Enterprise Security (endpoints, token, index, source_type), Elastic Security (endpoints, username, password, index), and Azure Blob Storage.
Who Can Take Which Part
Each part checks its permissions before it offers
| Permission | Parts |
|---|---|
| Device create | Receive FortiGate logs over UDP, Receive Palo Alto logs over UDP |
| Target create | Connect Microsoft Sentinel, Connect Splunk Enterprise Security, Connect Elastic Security, Connect Azure Blob Storage |
| Pipeline create and Advanced route create | Install the … pack and deploy its route, for each SIEM |
| Pipeline create | Add vendors to an installed … pack, for each SIEM |
| Advanced route edit | Choose CommonSecurityLog or ASIM, See what lands where in Splunk, See what lands where in Elastic, the three Send less to … parts, and the three Send a raw copy to Blob parts |
| Content Hub read | How autodiscovery recognises a vendor, See what a FortiGate line becomes, See what a PAN-OS line becomes |
What the Parts Change
The parts run in your own organization, not in a sandbox, and create and change real items.
Taken on a tenant, the parts:
- create a Syslog device
- create a target for the chosen SIEM (Microsoft Sentinel, Splunk Enterprise Security, or Elastic Security) and an Azure Blob Storage target
- install the SIEM's Automation and Normalization Pack with its advanced route, plus optional vendor packs (Fortinet FortiGate Pack; Syslog Vendor Autodiscovery Pack and Palo Alto Networks PAN-OS Pack)
- edit that route's configuration
The route parts open the route from the pack's page, through
Progress
Completed parts are saved per user, as for the other courses.