---
title: Sentinel
slug: sentinel
docTags: 
createdAt: 2023-05-23T05:23:47.000Z
---

### Prerequisite

- You have to get the [AIShield AI Security Monitoring App for Microsoft Sentinel](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/rbei.bgsw_aishield_sentinel?tab=Overview) from azure marketplace to get started with below steps.

### Detail steps:

**&#xA0;**&#x44;eploy[ AIShield - AI Security Monitoring for Microsoft Sentinel ](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/rbei.bgsw_aishield_sentinel?tab=overview) app to your Microsoft sentinel enabled log analytics workspace. Following component will be deployed with this installation. 

1. **Data connector:** Azure Sentinel enables you to use data connectors to configure connections with AIShield Product.&#x20;
2. **Parser**: Parser are built as user defined functions that transform data in existing table as the normalized schema.&#x20;
3. **Analytics rules:** Scheduled analytics rules are based on built-in queries written by AIShield team to create security alert/Incidents.&#x20;

Please follow below steps for AIShield - AI Security Monitoring connector installation:

 1. Go to the azure marketplace and search for AIShield - AI Security Monitoring App for Microsoft Sentinel and click on get it now.

::Image[]{src="https://api.archbee.com/api/optimize/9GPi9YtROlYnoq5fgmmJ8/e41DbBUlPZ-53d4A_7G9e_image.png" size="96" width="1600" height="655" position="center" caption="AIShield - AI Security Monitoring App for Microsoft Sentinel" alt="AIShield - AI Security Monitoring for Microsoft Sentinel " showCaption="true"}



2\. It will redirect to the solution installation page and click on create button.

::Image[ ]{src="https://api.archbee.com/api/optimize/9GPi9YtROlYnoq5fgmmJ8/25-B4UN3vwbOa5SeQya0C_image.png" size="84" width="1449" height="659" position="center" showCaption="false"}

After clicking on create, it will show you detailed components and details.

![](https://api.archbee.com/api/optimize/9GPi9YtROlYnoq5fgmmJ8/5XKT9WFjw6uVBeE-eF9ul_image.png)

Select the subscription and resource in which Log analytics workspace resides. After that review the details and click on create. It will deploy all the components into the sentinel enabled logs analytics workspace. 

You will be able to see deployed component using following steps. 

1. **Data Connector :&#x20;**&#xA0;Go to the data connector page and search for the AIShield you will be able to see data connector page
2. **Parser :&#x20;**&#x4C;og analytics workspace -> go to function -> You will able to see parser
3. **Analytics rule :&#x20;**&#x4D;icrosoft analytics is where you set up rules to find issues with the AI&#x20;

After setting up everything,you'll get two important codes from the AIShield data connector page in your Microsoft Sentinel workspace:&#x20;

1. &#x20;customer ID (azure\_log\_customer\_id)
2. shared key (azure\_log\_shared\_key)

![](https://api.archbee.com/api/optimize/9GPi9YtROlYnoq5fgmmJ8/4AR3e04lV8MrlgXlNerxW_image.png)

&#x20;You need to take these codes and put them into the AIShield Threat Informed Defense app.

Please go through the Readme.txt file provided by AIShield Threat Informed Endpoint Defense (EDR) and follow the below defense connector steps for setup.

## Defense connector

You can download the defense artifact after your job runs successfully. The defense artifact will contain the defense model in .h5 and .onnx formats, one Python file, and a readme file describing the steps to follow to use it. Assuming you have already downloaded the artifact, you can follow the steps below to configure the defense with Azure Sentinel and Splunk Connector.

AIShield provided Threat Informed Defense Model zip folder contains the following files.

&#x9;1\. Defense Model Architecture image
&#x9;2\. Defense Model Classification Report image
&#x9;3\. Defense Model Confusion Matrix Image
&#x9;4\. Defense Model (h5 format)
&#x9;5\. defense\_model (onxx format)
&#x9;6\. Predict.py
&#x20;   7\. ReadMe.txt


Following steps describe the procedure to integrate and test AIShield provided Threat Informed Defense Model.



### Step 1: Install Python Packages

```python
pip install numpy
pip install tqdm
pip install tensorflow
pip install cv2
```

### Step 2: Import AISDefenseModel and necessary libraries

```python
from predict import AISDefenseModel
import tensorflow
import cv2
import numpy as np
```

### Step 3: Load the TensorFlow model

defense\_model\_path variable is used to store the file path or location on the local system where a defense model  is expected to be found.

```python
defense_model = tensorflow.keras.models.load_model(defense_model_path)

```

### Step 4: Create AISDefenseModel with Connector

```python
model = AISDefenseModel(defense_model, azure_log_customer_id, azure_log_shared_key)
```

**Parameters**:

- `azure_log_customer_id`: Azure Object Id (Workspace Id) of your workspace to log event data.
- `azure_log_shared_key`: Primary Key of the Log Analytics workspace to log event data.

### Step 5: Test AISDefenseModel&#x20;

Load the necessary data and use AIShield provided attack data for testing the defense model.

```python
attack_data = load_data(attack_data_list)
model.predict(attack_data)
```

Once AIShield provided Threat Informed Endpoint Defense (EDR) app sending logs to Microsoft sentinel you will be able to see logs using parser name or table name\:L

AIShield or AIShield\_CL 

![](https://api.archbee.com/api/optimize/9GPi9YtROlYnoq5fgmmJ8/Cya-4fv0Ar1lYfmn-qTSq_image.png)

 If you have any questions or need any help related to this integration. Please get in touch with [aishield.contact@bosch.com](mailto\:aishield.contact@bosch.com) 
