Good day everyone!
So recently we have begun to ingest EPM log into MS Sentinel, and I have noticed a difference in the data we see in the console Analytics vs Sentinel. Firstly the integration was simple and straight forward. Once configured we began to see information flow into Sentinel. This is not a problem and seems to be working well, we used the CIM format.
What we are seeing is good, but it is nowhere near the information we see in the console analytics.
Example I will use is logons. We can see logons in both the analytics and Sentinel, however there is information missing in the information we see in Sentinel, namely privilege. So in the analytics I can see and search on the client privilege, and status of the account (domain, local), but in Sentinel I am not.
I just wanted to start a conversation with others who are using a SIEM with EPM or plan too int he near future. We could compare experiences and possibly see what in store for the future from Beyond Trust.
Thanks, and have a great day!
Scott



