Forum Discussion
gcorsini
Oct 31, 2021Copper Contributor
Log data for connecting and disconnecting Sentinel Data Connectors
Just wondering if anyone has any knowledge of where log data for connecting and disconnecting Sentinel Data connectors might be stored. We ran into this scenario in my production environment where the Azure Active Directory connectors for AuditLogs and SigninLogs were suddenly disconnected and no one has any record of when or why. I've since turned the connectors back on but I can't isolate the event or actor where the log was turned off.
Has anyone had any experience with this, or could point me to a doc where I might generate a query to find this event? I can see roughly when the logs were turned off, and they were off for over a week.
Without physically testing my self the AAD connector, going off the link below I would assume the logs should be in the Azure Activity Table. Ive made changes to the DNS connector recently which involved turning off/on and I could see the events in the logs. Hope this helps.
https://docs.microsoft.com/en-us/azure/sentinel/audit-sentinel-data
MICROSOFT SENTINEL DATA INCLUDED IN AZURE ACTIVITY LOGS
Operation:
DeletedInformation types:
Alert rules
Bookmarks
Data connectors
Incidents
Saved searches
Settings
Threat intelligence reports
Watchlists
Workbooks
WorkflowOperation:
UpdatedInformation types:
Alert rules
Bookmarks
Cases
Data connectors
Incidents
Incident comments
Threat intelligence reports
Workbooks
Workflow
- MattBurrowsBrass Contributor
Without physically testing my self the AAD connector, going off the link below I would assume the logs should be in the Azure Activity Table. Ive made changes to the DNS connector recently which involved turning off/on and I could see the events in the logs. Hope this helps.
https://docs.microsoft.com/en-us/azure/sentinel/audit-sentinel-data
MICROSOFT SENTINEL DATA INCLUDED IN AZURE ACTIVITY LOGS
Operation:
DeletedInformation types:
Alert rules
Bookmarks
Data connectors
Incidents
Saved searches
Settings
Threat intelligence reports
Watchlists
Workbooks
WorkflowOperation:
UpdatedInformation types:
Alert rules
Bookmarks
Cases
Data connectors
Incidents
Incident comments
Threat intelligence reports
Workbooks
Workflow