azure-monitor-security
Installation
SKILL.md
Azure Monitor & Log Analytics for Security
Microsoft Sentinel runs on a Log Analytics workspace. Defender for Cloud, Defender XDR hunting tables, Activity logs, and Diagnostic settings also flow there. The workspace strategy decides whether your security telemetry is complete, compliant, and affordable — or two of three.
This skill covers the security-side decisions in workspace design: tiering, retention, DCRs, RBAC, and cost.
When to use
Designing or refactoring the Log Analytics workspace(s) that back Sentinel and the broader security telemetry estate.
Do not use this skill for Sentinel detection authoring
(sentinel-detection-engineering), App Insights instrumentation
(appinsights-instrumentation), or non-security observability.