Description
[Option 2] - Using Azure Monitor Agent - You can stream all Exchange Security & Application Event logs from the Windows machines connected to your Microsoft Sentinel workspace using the Windows agent. This connection enables you to create custom alerts, and improve investigation.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Azure Log Analytics will be deprecated
Azure Log Analytics will be deprecated, to collect data from non-Azure VMs, Azure Arc is recommended. [Learn more](https://docs.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-install?tabs=ARMAgentPowerShell,PowerShellWindows,PowerShellWindowsArc,CLIWindows,CLIWindowsArc)
Detailled documentation
>**NOTE:** Detailled documentation on Installation procedure and usage can be found [here](https://aka.ms/MicrosoftExchangeSecurityGithub)
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
>**NOTE:** This solution is based on options. This allows you to choose which data will be ingest as some options can generate a very high volume of data. Depending on what you want to collect, track in your Workbooks, Analytics Rules, Hunting capabilities you will choose the option(s) you will deploy. Each options are independant for one from the other. To learn more about each option: ['Microsoft Exchange Security' wiki](https://aka.ms/ESI_DataConnectorOptions)
>This Data Connector is the **option 2** of the wiki.
1. Download and install the agents needed to collect logs for Microsoft Sentinel
Type of servers (Exchange Servers, Domain Controllers linked to Exchange Servers or all Domain Controllers) depends on the option you want to deploy.
Deploy Monitor Agents
This step is required only if it's the first time you onboard your Exchange Servers/Domain Controllers
**Deploy the Azure Arc Agent**
> [Learn more](https://docs.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-install?tabs=ARMAgentPowerShell,PowerShellWindows,PowerShellWindowsArc,CLIWindows,CLIWindowsArc)
2. [Option 2] Security/Application/System logs of Exchange Servers
The Security/Application/System logs of Exchange Servers are collected using Data Collection Rules (DCR).
Security Event log collection
Data Collection Rules - Security Event logs
**Enable data collection rule for Security Logs**
Security Events logs are collected only from **Windows** agents.
1. Add Exchange Servers on *Resources* tab.
2. Select Security log level
> **Common level** is the minimum required. Please select 'Common' or 'All Security Events' on DCR definition.
Application and System Event log collection
Enable data collection rule
> Application and System Events logs are collected only from **Windows** agents.
Option 1 - Azure Resource Manager (ARM) Template (Prefered method)
Use this method for automated deployment of the DCR.
1. Click the **Deploy to Azure** button below.
[](https://aka.ms/sentinel-ESI-DCROption2-azuredeploy)
2. Select the preferred **Subscription**, **Resource Group** and **Location**.
3. Enter the **Workspace Name** 'and/or Other required fields'.
>4. Mark the checkbox labeled **I agree to the terms and conditions stated above**.
5. Click **Purchase** to deploy.
Option 2 - Manual Deployment of Azure Automation
Use the following step-by-step instructions to deploy manually a Data Collection Rule.
A. Create DCR, Type Event log
1. From the Azure Portal, navigate to [Azure Data collection rules](https://portal.azure.com/#view/Microsoft_Azure_Monitoring/AzureMonitoringBrowseBlade/~/dataCollectionRules).
2. Click **+ Create** at the top.
3. In the **Basics** tab, fill the required fields, Select Windows as platform type and give a name to the DCR.
4. In the **Resources** tab, enter you Exchange Servers.
5. In 'Collect and deliver', add a Data Source type 'Windows Event logs' and select 'Basic' option.
6. For Application, select 'Critical', 'Error' and 'Warning'. For System, select Critical/Error/Warning/Information.
7. 'Make other preferable configuration changes', if needed, then click **Create**.
Assign the DCR to all Exchange Servers
Add all your Exchange Servers to the DCR
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
ESI-Opt2ExchangeServersEventLogs
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC