An inconsistency was detected in the sources: variants or an invalid file. Check the files and commit shown below.
Description
Event data connector allows for the export of its Windows event logs (i.e. Indicators of Exposure and Indicators of Compromise) to Azure Sentinel in real time.
It provides a data parser to manipulate the Windows event logs more easily. The different workbooks ease your Active Directory security monitoring and provide different ways to visualize the data. The analytic templates allow to automate responses regarding different events, exposures, or attacks.
- Declared status
- 1
- Declared author / publisher
- PROVIDER NAME
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
>This data connector depends on a parser based on a Kusto Function to work as expected. [Follow these steps](Link to Kusto Function on Azure Sentinel GitHub) to create the Kusto Functions alias, **enter the Kusto Function alias**
1. Configure <enter the name of connector server> to send Windows event logs to your Azure Sentinel Workspace
On your **enter the name of connector server ** install the Microsoft agent for Windows.
2. Install and onboard the Microsoft agent for Windows
You can skip this step if you have already installed the Microsoft agent for Windows
Choose where to install the agent:
Install agent on <enter the name of connector server>
Download the agent on the relevant machine and follow the instructions.
3. Configure the <enter the name of connector server> Windows event logs to be collected by the agent
Configure the agent to collect the logs.
1. Under workspace advanced settings **Configuration**, select **Data** and then **Windows Event Logs**.
2. Select **Go to Agents configuration** and click **Add Windows event log**.
3. Enter **<enter the operational log name>** as the log name to be collected and click **Apply**
> You should now be able to receive logs in the *Windows event log* table, log data can be parsed using the **<enter the Kusto Function alias>** function, used by all query samples, workbooks and analytic templates.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
ProviderNameApplianceName
Additional source files 1
DataConnectors/Templates/Connector_Event_template.jsonsource ↗GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC