Forum Discussion

gcorsini's avatar
gcorsini
Copper Contributor
Oct 31, 2021
Solved

Log data for connecting and disconnecting Sentinel Data Connectors

Just wondering if anyone has any knowledge of where log data for connecting and disconnecting Sentinel Data connectors might be stored. We ran into this scenario in my production environment where the Azure Active Directory connectors for AuditLogs and SigninLogs were suddenly disconnected and no one has any record of when or why. I've since turned the connectors back on but I can't isolate the event or actor where the log was turned off. 

 

Has anyone had any experience with this, or could point me to a doc where I might generate a query to find this event? I can see roughly when the logs were turned off, and they were off for over a week.

  • gcorsini 

    Without physically testing my self the AAD connector, going off the link below I would assume the logs should be in the Azure Activity Table. Ive made changes to the DNS connector recently which involved turning off/on and I could see the events in the logs. Hope this helps.

     

    https://docs.microsoft.com/en-us/azure/sentinel/audit-sentinel-data

     

    MICROSOFT SENTINEL DATA INCLUDED IN AZURE ACTIVITY LOGS

    Operation:
    Deleted

     

    Information types:
    Alert rules
    Bookmarks
    Data connectors
    Incidents
    Saved searches
    Settings
    Threat intelligence reports
    Watchlists
    Workbooks
    Workflow

     

    Operation:
    Updated

     

    Information types:
    Alert rules
    Bookmarks
    Cases
    Data connectors
    Incidents
    Incident comments
    Threat intelligence reports
    Workbooks
    Workflow

  • MattBurrows's avatar
    MattBurrows
    Brass Contributor

    gcorsini 

    Without physically testing my self the AAD connector, going off the link below I would assume the logs should be in the Azure Activity Table. Ive made changes to the DNS connector recently which involved turning off/on and I could see the events in the logs. Hope this helps.

     

    https://docs.microsoft.com/en-us/azure/sentinel/audit-sentinel-data

     

    MICROSOFT SENTINEL DATA INCLUDED IN AZURE ACTIVITY LOGS

    Operation:
    Deleted

     

    Information types:
    Alert rules
    Bookmarks
    Data connectors
    Incidents
    Saved searches
    Settings
    Threat intelligence reports
    Watchlists
    Workbooks
    Workflow

     

    Operation:
    Updated

     

    Information types:
    Alert rules
    Bookmarks
    Cases
    Data connectors
    Incidents
    Incident comments
    Threat intelligence reports
    Workbooks
    Workflow

Resources