A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Sentinel Data Lake – Features unavailable for a specific workspace
I have a question regarding the configuration of the Sentinel Data Lake.
A specific workspace does not appear under the following workspace scope in the Defender portal:
Data lake exploration > KQL queries
Could you tell me how to make it appear there, as well as the possible reasons why it may not be displayed?
Other workspaces are shown under the same workspace scope.
However, the target workspace does appear under:
Data lake exploration > Search & Restore
Below is the information about the current configuration.
◆ Data Lake Setup — (1)
・Subscription: Same as the target workspace
・Resource Group: Same as the target workspace
・Location: japaneast (same as the target workspace)
・After completing the Data Lake setup, the target workspace was connected to Microsoft Defender XDR — (2)
・After connection, the target workspace was set as Primary — (3)
◆ Workspace Connection
・Status: Connected
◆ Role assignments of the account used for configuration / verification
(1) During initial setup:
Entra role: Security Administrator
Azure roles:
・Contributor
Scope: Subscription (same as the target workspace)
(2) and (3): During connection, primary assignment, and verification
Entra role: Security Administrator
Azure roles:
・Microsoft Sentinel Contributor
Scope: Subscription (same as the target workspace)
・User Access Administrator
Scope: Subscription (same as the target workspace)
Condition: Allow assignment of roles other than Owner, User Access Administrator, and Role Based Access Control Administrator
◆ Actions already tried
・Disconnected workspace -> reconnected -> set as primary again (multiple times)
Questions:
- The reason why the workspace does not appear under: Defender portal > Data lake exploration > KQL queries
- The procedure required to make the workspace appear under: Defender portal > Data lake exploration > KQL queries