Forum Discussion

kenvb's avatar
kenvb
Copper Contributor
Apr 27, 2022
Solved

How to get CEF-based logs into sentinel (LA, AMA or Logstash) AND use the data connectors.

Do I still need the old log analytics agent to ingest CEF-logs and setup a (fortinet) dataconnector to get proper parsed logs into "commonsecuritylogs"  as it seems the AMA can't do that yet (for now...
  • Clive_Watson's avatar
    Clive_Watson
    Apr 28, 2022
    That's a fair point, however this is the method Microsoft is supporting today.
    If you do something different, you have to support it, and you may also have to adapt the Rules, Workbooks or Playbooks to look at the custom table you are ingesting. If you can bring the data into CommonSecurityLog then that's not an issue.

Resources