↳ GitHub sourceConnector

Amazon Web Services Elastic Load Balancing (via Codeless Connector Framework)

Description

The AWS Elastic Load Balancing (ELB) connector for Microsoft Sentinel allows you to ingest access logs and flow logs from AWS Application Load Balancers (ALB), Network Load Balancers (NLB), and Gateway Load Balancers (GLB) into Microsoft Sentinel. These logs provide detailed information about requests processed by your load balancers and VPC traffic flows, enabling security monitoring, threat detection, and traffic analysis.
Declared status
1
Declared author / publisher
Amazon Web Services

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
AWS IAM Role ARN and SQS Queue
An **AWS IAM Role ARN** with cross-account access and an **SQS Queue URL** configured for S3 event notifications are required. See [AWS ELB connector documentation](https://learn.microsoft.com/en-us/azure/sentinel/connect-aws) for setup instructions.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Add new collector
Add new collector
Account details
Role ARN
Queue URL
Data type
ALB Access Logs
NLB Access Logs
NLB Flow Logs
GLB Flow Logs

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
AWSELBConnector
Additional source files 2Solutions/AWS ELB/Data Connectors/AWSELBConnector_CCF/AWSELBConnector_ConnectorDefinition.jsonsource ↗Solutions/AWS ELB/Data/Solution_AWSELB.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.