<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Documentation on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/documentation/</link><description>Recent content in Documentation on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Mon, 01 Jun 2026 05:33:21 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/documentation/index.xml" rel="self" type="application/rss+xml"/><item><title>Oracle Cloud Infrastructure CCF Connector: IAM Permissions Guidance Added</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14347/</link><pubDate>Mon, 01 Jun 2026 05:33:21 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14347/</guid><description>OCI connector UI updated with explicit IAM policy requirements for stream consumption authorization alongside API signing key authentication.</description></item><item><title>Google Threat Intelligence Solution: Custom Connector Deployment Prerequisites Clarified</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14267/</link><pubDate>Wed, 27 May 2026 06:35:46 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14267/</guid><description>Solution metadata updated to warn customers that Playbooks require manual deployment of the GTI custom Logic Apps connector before use.</description></item><item><title>Microsoft Entra ID Table Rename: Hunting Queries Updated for Current Schema</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</link><pubDate>Mon, 18 May 2026 05:36:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14186/</guid><description>12 hunting queries updated to use EntraIdSignInEvents and EntraIdSpnSignInEvents tables, replacing deprecated AADSignInEventsBeta and AADSpnSignInEventsBeta references.</description></item><item><title>Visa Threat Intelligence: Connector Description Update for Certification</title><link>http://sentinelchangelog.net/posts/2026-05-05-pr-14206/</link><pubDate>Tue, 05 May 2026 16:50:36 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-05-pr-14206/</guid><description>Updated Data Connector description in Visa Threat Intelligence solution to resolve certification failure.</description></item><item><title>Entra ID Brute Force Detection: Renamed for Broader Windows Device Coverage</title><link>http://sentinelchangelog.net/posts/2026-04-30-pr-14162/</link><pubDate>Thu, 30 Apr 2026 11:04:41 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-30-pr-14162/</guid><description>Analytic rule renamed from Cloud PC-specific to cover all Entra-authenticated Windows devices, clarifying detection scope without logic changes.</description></item><item><title>Logstash Output Plugin: Documentation Update for Version 2.1.1</title><link>http://sentinelchangelog.net/posts/2026-04-30-pr-14164/</link><pubDate>Thu, 30 Apr 2026 08:35:40 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-30-pr-14164/</guid><description>Version bump to 2.1.1 with efficiency improvements noted but no connector logic changes.</description></item><item><title>Microsoft Sentinel Logstash Plugin: Documentation Update Reveals Major Architecture Changes</title><link>http://sentinelchangelog.net/posts/2026-04-20-pr-14084/</link><pubDate>Mon, 20 Apr 2026 06:03:15 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-20-pr-14084/</guid><description>Documentation updated for Logstash output plugin to reflect version 2.1.0 with Ruby-to-Java refactor, managed identity support, and closed-source transition.</description></item><item><title>Island Enterprise Browser V2 Connector: Documentation Clarity Improvements</title><link>http://sentinelchangelog.net/posts/2026-04-09-pr-13993/</link><pubDate>Thu, 09 Apr 2026 08:47:10 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-09-pr-13993/</guid><description>Updated Island connector titles and descriptions to reduce confusion between legacy V1 and current V2 connectors.</description></item><item><title>Data Connector 64 KB Field Truncation: Silent Data Loss Risk Documented</title><link>http://sentinelchangelog.net/posts/2026-04-08-pr-14008/</link><pubDate>Wed, 08 Apr 2026 21:06:23 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-08-pr-14008/</guid><description>Microsoft Sentinel now documents a critical platform limitation where individual fields exceeding 64 KB are silently truncated during ingestion, creating blind spots in large payload analysis.</description></item><item><title>Azure Resource Graph: Table Name Standardization for Query Consistency</title><link>http://sentinelchangelog.net/posts/2026-04-08-pr-13971/</link><pubDate>Wed, 08 Apr 2026 05:17:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-08-pr-13971/</guid><description>Azure Resource Graph connector updated table labels to align with Table Management naming conventions, ensuring consistent query references.</description></item><item><title>Detection Template Validation: connectorId Enforcement Added to Review Process</title><link>http://sentinelchangelog.net/posts/2026-04-02-pr-13959/</link><pubDate>Thu, 02 Apr 2026 07:33:15 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-02-pr-13959/</guid><description>Detection authoring guidelines now require validation of connectorId values against the official repository allowlist to prevent invalid connector references.</description></item><item><title>Microsoft Copilot Connector: Updated Product Scope Description</title><link>http://sentinelchangelog.net/posts/2026-03-20-pr-13842/</link><pubDate>Fri, 20 Mar 2026 07:56:13 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-20-pr-13842/</guid><description>Clarifies connector description to specify M365 Copilot and Security Copilot coverage alongside general improvements.</description></item><item><title>Google Kubernetes Engine Connector: Documentation Update Links to Official Microsoft Learn</title><link>http://sentinelchangelog.net/posts/2026-03-01-pr-13720/</link><pubDate>Sun, 01 Mar 2026 05:27:29 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-01-pr-13720/</guid><description>Google Kubernetes Engine connector documentation updated to reference official Microsoft Learn guides instead of personal repositories.</description></item><item><title>Logstash Connector: Extended Version Support for Newer Logstash Releases</title><link>http://sentinelchangelog.net/posts/2026-02-27-pr-13714/</link><pubDate>Fri, 27 Feb 2026 10:26:15 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-27-pr-13714/</guid><description>Documentation update adds support for Logstash versions 8.19.2, 9.0.8, 9.1.10, and 9.2.4-9.2.5.</description></item><item><title>Azure Activity: Hunting Query Documentation Enhancement for Custom Script Extensions</title><link>http://sentinelchangelog.net/posts/2026-02-26-pr-13705/</link><pubDate>Thu, 26 Feb 2026 04:54:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-26-pr-13705/</guid><description>Minor documentation improvement clarifying protected settings visibility in Custom Script Extension hunting query.</description></item><item><title>JoeSandbox Solution: Updated Deployment Links and Removed Manual Installation Steps</title><link>http://sentinelchangelog.net/posts/2026-02-13-pr-13623/</link><pubDate>Fri, 13 Feb 2026 11:30:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-13-pr-13623/</guid><description>JoeSandbox solution deployment documentation updated with corrected Azure links and streamlined automated deployment options.</description></item><item><title>ASIM Authentication Schema: NetworkCleartext SubType Added</title><link>http://sentinelchangelog.net/posts/2026-02-12-pr-13518/</link><pubDate>Thu, 12 Feb 2026 17:55:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-12-pr-13518/</guid><description>ASIM Authentication schema expanded to include NetworkCleartext authentication subtype for cleartext password events.</description></item><item><title>Documentation Fix: Broken Links Resolved in Microsoft Entra ID and Network Session Essentials</title><link>http://sentinelchangelog.net/posts/2026-02-06-pr-13510/</link><pubDate>Fri, 06 Feb 2026 09:21:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-06-pr-13510/</guid><description>Customer-reported broken links fixed in analytic rule descriptions with corrected MITRE technique references and restored documentation.</description></item><item><title>Solutions Analyzer: Enhanced Documentation with Lake-Only Ingestion and Statistics Features</title><link>http://sentinelchangelog.net/posts/2026-02-04-pr-13478/</link><pubDate>Wed, 04 Feb 2026 17:04:53 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-02-04-pr-13478/</guid><description>Comprehensive documentation tool update adds lake-only ingestion tracking, collection methods index, and enhanced connector association analysis.</description></item><item><title>Azure DevOps Auditing Solution: Description Text Cleanup and Repackaging</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-13488/</link><pubDate>Thu, 22 Jan 2026 11:11:47 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-13488/</guid><description>Azure DevOps Auditing solution repackaged with updated description removing outdated streaming configuration text references.</description></item><item><title>Microsoft Defender XDR: SUNSPOT Detection Rule Documentation Update</title><link>http://sentinelchangelog.net/posts/2026-01-22-pr-13485/</link><pubDate>Thu, 22 Jan 2026 11:09:59 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-22-pr-13485/</guid><description>Updated SUNSPOT malware detection rule with corrected reference link formatting and MITRE technique mapping fixes across multiple solutions.</description></item><item><title>Compliance Solutions: Microsoft Exchange Product Link Rebrand Update</title><link>http://sentinelchangelog.net/posts/2026-01-21-pr-13341/</link><pubDate>Wed, 21 Jan 2026 05:20:24 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-21-pr-13341/</guid><description>NIST SP 800-53 and Zero Trust compliance workbooks updated with current Microsoft Defender for Office 365 documentation links following EOP rebrand.</description></item><item><title>VMware ESXi Solution: Broken Link Removed</title><link>http://sentinelchangelog.net/posts/2026-01-05-pr-13379/</link><pubDate>Mon, 05 Jan 2026 21:31:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-01-05-pr-13379/</guid><description>Documentation maintenance removing broken link from VMware ESXi solution.</description></item><item><title>Microsoft Entra ID Playbooks: API Permission Updates for Session Revocation</title><link>http://sentinelchangelog.net/posts/2025-12-15-pr-13236/</link><pubDate>Mon, 15 Dec 2025 12:07:03 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-15-pr-13236/</guid><description>Updates Revoke-AADSignInSessions playbook documentation to use correct User.RevokeSessions.All permissions instead of broader User.ReadWrite.All.</description></item><item><title>AbuseIPDB Playbooks: Typo Fixes and Logo Source Update</title><link>http://sentinelchangelog.net/posts/2025-12-09-pr-13137/</link><pubDate>Tue, 09 Dec 2025 07:58:52 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-09-pr-13137/</guid><description>Minor documentation and configuration fixes for AbuseIPDB playbooks including corrected image source and typo corrections.</description></item><item><title>Solutions Analyzer Tool: Automated Connector Documentation Generation</title><link>http://sentinelchangelog.net/posts/2025-12-04-pr-13234/</link><pubDate>Thu, 04 Dec 2025 19:05:29 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-12-04-pr-13234/</guid><description>Solutions Analyzer tool enhanced to generate markdown documentation files for all 1000+ connectors in addition to CSV output.</description></item><item><title>Microsoft Entra ID Assets: Fixing Product Name Typo in Data Connector</title><link>http://sentinelchangelog.net/posts/2025-10-29-pr-12955/</link><pubDate>Wed, 29 Oct 2025 08:22:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-29-pr-12955/</guid><description>Fixed typo in Microsoft Entra ID Assets connector title and updated description to use correct Microsoft Sentinel branding.</description></item><item><title>VMRay: Updated Deployment URLs and Documentation for Threat Intelligence Connector</title><link>http://sentinelchangelog.net/posts/2025-10-13-pr-12891/</link><pubDate>Mon, 13 Oct 2025 06:01:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-13-pr-12891/</guid><description>VMRay solution updated deployment URLs and documentation to use short links for better maintainability.</description></item><item><title>Illumio Insight Connectors: Enhanced Documentation and Polling Configuration</title><link>http://sentinelchangelog.net/posts/2025-10-06-pr-12886/</link><pubDate>Mon, 06 Oct 2025 08:15:08 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-10-06-pr-12886/</guid><description>Documentation improvements and polling frequency adjustment enhance user experience for Illumio threat analysis deployment.</description></item></channel></rss>