Installing the Microsoft Sentinel Extension
To install the Microsoft Sentinel extension, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the menu
icon to open the Global menu.The Global menu is displayed with menu items represented as cards.
-
In the Extensions card, click Manage.
The Extensions page is displayed, along with the installed and available extensions under their respective tabs.
Figure 1: Available Extensions Tab
-
Under the Available Extensions tab, in the Microsoft Sentinel card, click Install.
The Microsoft Sentinel installation side panel is displayed.
Figure 2: Microsoft Sentinel Installation Side Panel
-
Enter the required details as follows:
-
Name—Enter a name for the Microsoft Sentinel extension instance.
-
Tenant ID—Enter the tenant ID for the Microsoft Sentinel extension instance.
-
Client ID—Enter the client ID for the Microsoft Sentinel extension instance.
-
Client Secret—Enter the client secret for the Microsoft Sentinel extension instance.
-
Data Collection—Enter the Endpoint URL and Rule ID for the Microsoft Sentinel extension instance.
-
Table Mapping—Select Clients as the Data Source. This is a mandatory field. A data source indicates the location in HPE Aruba Networking Central from where data is to be exported to Microsoft Sentinel.
-
Enter a table name in the Map To Table field. This is a mandatory field. An index name must consist of only numbers, letters, underscores, and hyphens. An index name cannot contain the word kvstore.
Note:The table name is automatically prefixed with Custom- and suffixed with _CL. For example, if the table name is june10_table, it becomes Custom-june10_table_CL.
-
Click the plus
or delete
icons to add or delete a Table Mapping configuration.
-
Note:The previously mentioned details are obtained as follows:
-
The client ID (Application (client) ID) and <tenant-ID> (Directory (tenant) ID) are available on the Overview page of the installed Sentinel-Simple Certificate Enrollment Protocol (SCEP) application in the Microsoft Azure Active Directory portal.
-
The secret (Value) is available on the Certificates & secrets > New Client Secret page of the installed Sentinel-Simple Certificate Enrollment Protocol (SCEP) application in the Microsoft Azure Active Directory portal.
For more information, see Microsoft Sentinel Integration Prerequisites.
-
-
Click Install.
-
If installed successfully, the Installed Extensions tab displays a Microsoft Sentinel card with the defined instance name and an Active status.
Figure 3: Active Microsoft Sentinel card
-
If there is an issue with the extension, the Installed Extensions tab, displays a Microsoft Sentinel card with the defined instance name and an Inactive status.
Clicking the card displays the side panel with the error message at the top.
-