Forum Discussion

omrip's avatar
omrip
Copper Contributor
Oct 23, 2019

forward logs to Log Analytics

how do i forward logs and alerts generated from MS Defender Security Center to Log analytics to be used in Sentinel ?

there is an on preview connector on sentinel but i dont seem to find the configuration on the Defender security center side?

 

tnx

    • BobsYourUncledbroggy's avatar
      BobsYourUncledbroggy
      Copper Contributor

      Hi Jan Geisbauer ,

      So Sentinel will receive the ALERTS by using the built in connector, but what if you want the ATP EVENTS?

      For example if you want to query DeviceLogonEvents in order to track admin logins - sure I could query them in Defender but I want everything in Sentinel's workspace.

      Suggestions?

Resources