2.9 Security Intelligence

The correlation capability of Sentinel provides you the ability to look for known patterns of activity, which you can analyze for security, compliance, or any other reason. The Security Intelligence capability looks for activity that is out of the ordinary, which might be malicious, but does not match any known pattern.

The Security Intelligence feature in Sentinel focuses on statistical analysis of time series data to enable analysts to identify and analyze anomalies, either by an automated statistical engine or by visual representation of the statistical data for manual interpretation. For more information, see Analyzing Trends in Data in the Sentinel User Guide.