Description
The PROVIDER NAME APPLIANCE NAME data connector ingests Syslog events from APPLIANCE NAME into Microsoft Sentinel. Logs are collected using the Azure Monitor Agent (AMA) via the Microsoft **Syslog via AMA** solution, which must be installed in your workspace before configuring this connector.
[Learn more about the Syslog via AMA connector >](https://learn.microsoft.com/azure/sentinel/connect-syslog)
- Declared status
- 1
- Declared author / publisher
- PROVIDER NAME
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
write permission is required.
Workspace
Workspace
To collect data from non-Azure VMs, they must have Azure Arc installed and enabled. [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-install)
The **Syslog via AMA** solution must be installed in your Microsoft Sentinel workspace. [Install from Microsoft Marketplace](https://marketplace.microsoft.com/en-us/product/azuresentinel.azure-sentinel-solution-syslog)
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Configure APPLIANCE NAME to forward Syslog messages
Configure APPLIANCE NAME to forward Syslog messages to a Linux log forwarder machine on port 514 UDP/TCP.
> Replace this step with your product-specific instructions for enabling Syslog output. Include the relevant facility and severity settings your product uses, the destination IP/hostname of the log forwarder, and any product-side configuration steps the customer must complete.
2. Install the Syslog via AMA solution
This connector relies on the Microsoft **Syslog via AMA** solution to collect Syslog data into your workspace using the Azure Monitor Agent. If you have not already installed it, install it from the Microsoft Marketplace and create a Data Collection Rule (DCR) that includes the Syslog facilities forwarded by APPLIANCE NAME.
[Install Syslog via AMA from Microsoft Marketplace](https://marketplace.microsoft.com/en-us/product/azuresentinel.azure-sentinel-solution-syslog)
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
ProviderNameAppliance
Additional source files 1
DataConnectors/Templates/Connector_Syslog_template.jsonsource ↗GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC