Updating the Microsoft Sentinel Extension

To update the Microsoft Sentinel extension, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the menu icon to open the Global menu.

    The Global menu is displayed with menu items represented as cards.

  2. In the Extensions card, click Manage.

    The Extensions page is displayed, along with the installed and available extensions under their respective tabs.

  3. Under the Installed Extensions tab, click the installed Microsoft Sentinel card.

    The Microsoft Sentinel Configuration side panel is displayed.

    Figure 1: Microsoft Sentinel Configuration Side Panel

  4. Edit the required details as follows:

    • Name—The name of the Microsoft Sentinel extension is grayed out and cannot be edited.

    • Tenant ID—Enter the tenant ID for the Microsoft Sentinel client profile.

    • Client ID—Enter the client ID for the Microsoft Sentinel client profile.

    • Client Secret—Enter the password for the Microsoft Sentinel client profile.

    • Data Collection—Enter the Endpoint URL and Rule ID for the Microsoft Sentinel for the Microsoft Sentinel client profile.

    • Table Mapping—Select Clients as the Data Source. This is a mandatory field. A data source indicates the location in HPE Aruba Networking Central from where data is to be exported to Microsoft Sentinel.

      • Enter a table name in the Map To Table field. This is a mandatory field. An index name must consist of only numbers, lowercase letters, underscores, and hyphens. An index name cannot contain the word kvstore.

        Note:

        The table name is automatically prefixed with Custom- and suffixed with _CL. For example, if the table name is june10_table, it becomes Custom-june10_table_CL.

      • Click the plus or delete icons to add or delete a Data Mapping configuration.

  5. Click Update.