Hey!
Check this out -https://techcommunity.microsoft.com/blog/microsoftsentinelblog/table-talk-sentinel%E2%80%99s-new-threatintel-tables-explained/4440273
I thing it will help you.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Environment:
ThreatIntelligenceIndicator
(old/deprecated) and ThreatIntelIndicators
(new)Problem Description:
I'm experiencing duplicate data ingestion in my Sentinel workspace from the TAXII connector. There are two tables being populated with the same threat intelligence data:
ThreatIntelligenceIndicator
(the old table, which has been deprecated by Microsoft)ThreatIntelIndicators
(the new table introduced as a replacement)This duplication is causing unnecessary increases in data ingestion costs, as the same intel is being stored twice.
What I've Tried:
ThreatIntelligenceIndicator
table continues to ingest data.Question:
How can I completely stop data ingestion into the deprecated ThreatIntelligenceIndicator
table while ensuring that all threat intel data is only ingested into the new ThreatIntelIndicators
table? Are there any additional steps beyond uninstalling from the Content Hub, such as disabling workflows, updating configurations, or purging legacy connectors?
Any guidance, scripts, or documentation references would be greatly appreciated to help reduce these redundant costs. Thanks!
Hey!
Check this out -https://techcommunity.microsoft.com/blog/microsoftsentinelblog/table-talk-sentinel%E2%80%99s-new-threatintel-tables-explained/4440273
I thing it will help you.