Common Event Format (CEF) via AMA connector for Microsoft Sentinel

Common Event Format (CEF) is an industry standard format on top of Syslog messages, used by many security vendors to allow event interoperability among different platforms. By connecting your CEF logs to Microsoft Sentinel, you can take advantage of search & correlation, alerting, and threat intelligence enrichment for each log. For more information, see the Microsoft Sentinel documentation.

Connector attributes

Connector attribute Description
Log Analytics table(s) CommonSecurityLog
Data collection rules support Azure Monitor Agent DCR
Supported by Microsoft Corporation

Next steps

For more information, go to the related solution in the Azure Marketplace.