Ingest Data Sources in Microsoft Sentinel
Unlock the complete study guide + 1,040 practice questions across 16 full exams.
Bundled into the existing Microsoft Certified: Security Operations Analyst Associate premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- The ingestion model: source to connector to table
- Identify which data sources to ingest
- Install and use Content hub solutions
- Configure Microsoft connectors for Azure resources
- Plan and configure Syslog and CEF collection
- Collect Windows Security events with DCRs and WEF
- Create custom log tables in the workspace
- Monitor and optimize data ingestion
Picking a Sentinel ingestion mechanism by source
| Mechanism | What it collects | Agent needed | Configured by |
|---|---|---|---|
| Native data connector (Content hub) | Microsoft services + major clouds (Entra ID, M365, Defender XDR, AWS, GCP) | No agent (service-to-service) | Install solution, click Connect |
| AMA Syslog / CEF DCR | Network appliances: firewalls, proxies, IDS over Syslog/CEF | AMA on a Linux forwarder VM | Data collection rule (facility/severity filter) |
| AMA Windows-event DCR | Windows Security/System/Application events, optionally via WEF | AMA on Windows hosts or WEF collector | Data collection rule (XPath filter) |
| Custom _CL table | Anything with no built-in connector (in-house apps, niche tools) | AMA text-log DCR or none (API) | Logs Ingestion API or custom DCR |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
References
- What is Microsoft Sentinel SIEM?
- Azure Monitor Agent Overview
- Log Analytics Agent Migration
- Best practices for data collection in Microsoft Sentinel
- Discover and deploy Microsoft Sentinel out-of-the-box content from Content hub
- Ingest Microsoft Defender for Cloud alerts into Microsoft Sentinel
- Find your Microsoft Sentinel data connector
- Ingest syslog and CEF messages to Microsoft Sentinel - AMA
- Find your Microsoft Sentinel data connector
- Logs Ingestion API in Azure Monitor
- Transformations in Azure Monitor
- Manage and monitor costs for Microsoft Sentinel