Forum Discussion

Sand_Sentinel87's avatar
Sand_Sentinel87
Copper Contributor
Jul 04, 2024

Sentinel Log Sources or asset list Information

In Sentinel as like any other SIEM, how do we get the complete list of log sources which are integrated along with some required fields like Device Vendor, Device Product, Host name/Computer, IP address.

Is there any workbook or KQL which provides this information.

  • Clive_Watson's avatar
    Clive_Watson
    Bronze Contributor

    Sand_Sentinel87 

     

    Many workbooks would cover this (or the main parts), maybe start with "Workspace usage" in the Content hub.  Both the "Workspace Info" and "CEF Tabs" (under [Cost Analysis]) display this data 

     

Resources