Une incohérence a été détectée dans les sources : variantes ou fichier invalide. Vérifiez les fichiers et le commit indiqués ci-dessous.
Description
Event data connector allows for the export of its Windows event logs (i.e. Indicators of Exposure and Indicators of Compromise) to Azure Sentinel in real time.
It provides a data parser to manipulate the Windows event logs more easily. The different workbooks ease your Active Directory security monitoring and provide different ways to visualize the data. The analytic templates allow to automate responses regarding different events, exposures, or attacks.
- Statut déclaré
- 1
- Auteur / éditeur déclaré
- PROVIDER NAME
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Permissions déclarées
read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Instructions du connecteur
Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.
>This data connector depends on a parser based on a Kusto Function to work as expected. [Follow these steps](Link to Kusto Function on Azure Sentinel GitHub) to create the Kusto Functions alias, **enter the Kusto Function alias**
1. Configure <enter the name of connector server> to send Windows event logs to your Azure Sentinel Workspace
On your **enter the name of connector server ** install the Microsoft agent for Windows.
2. Install and onboard the Microsoft agent for Windows
You can skip this step if you have already installed the Microsoft agent for Windows
Choose where to install the agent:
Install agent on <enter the name of connector server>
Download the agent on the relevant machine and follow the instructions.
3. Configure the <enter the name of connector server> Windows event logs to be collected by the agent
Configure the agent to collect the logs.
1. Under workspace advanced settings **Configuration**, select **Data** and then **Windows Event Logs**.
2. Select **Go to Agents configuration** and click **Add Windows event log**.
3. Enter **<enter the operational log name>** as the log name to be collected and click **Apply**
> You should now be able to receive logs in the *Windows event log* table, log data can be parsed using the **<enter the Kusto Function alias>** function, used by all query samples, workbooks and analytic templates.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
629d1d3↗- Identifiant source
ProviderNameApplianceName
Autres fichiers source 1
DataConnectors/Templates/Connector_Event_template.jsonsource ↗GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC