Migrating Sentinel DNS event connector from legacy agent to AMA

Louise Atyeo 20 Reputation points
2024-06-05T10:08:43.27+00:00

Hi

I am in the process of migrating the Sentinel Windows security and DNS data connectors from the legacy agent to AMA.

We use the DNS audit log 519 events to resolve device names from ip addresses where the device name is not returned in a lookup query. However, the DNS events via AMA connector currently only supports analytic events, so we will no longer be receiving these audit events.

Is there another way to ingest the DNS audit events?

Otherwise is support for audit events in the roadmap for the DNS via AMA connector?

Thanks

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,023 questions
{count} votes

Accepted answer
  1. Akshay-MSFT 17,011 Reputation points Microsoft Employee
    2024-06-06T08:33:10.29+00:00

    @Louise Atyeo

    Thank you for posting your query on Microsoft Q&A, I am currently getting the ask reviewed internally and will get back to you with further inputs.

    Update 1:

    Thank you for your time and patience, I was able to get this reviewed and got the following update from dev team:

    As per current design DNS events via the AMA connector only support analytic events, not audit events.

    However, adding the collection of Windows DNS audit events in currently on the roadmap and private preview would be out soon for customer's feedback. Currently we don't have any ETA on the availability.

    If you don't have any further queries and the suggested answer is as per your business need, please "Accept the answer", This will help us and others in the community as well.

    Thanks,

    Akshay Kaushik


0 additional answers

Sort by: Most helpful