Microsoft Sentinel with Object Storage

Sean Hartling 1 Reputation point
2022-09-28T14:34:54.793+00:00

Will Microsoft Sentinel work with a Object Storage solution other then Azure?
Is it possible for Sentinel connectors to point to different S3/Object storage solutions?

Microsoft Security Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,906 Reputation points Microsoft Employee Moderator
    2022-09-28T22:59:38.88+00:00

    @Sean Hartling
    Thank you for your post!

    When it comes to integrating Microsoft Sentinel with different storage solutions, for example Amazon S3 Storage, you should be able to leverage our new AWS S3 connector.

    Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data
    Note: The Amazon Web Services S3 connector is currently in Public preview. For now, you can use this connection to ingest VPC Flow Logs, GuardDuty findings, and AWS CloudTrail.

    This connector is available in two versions: the legacy connector for CloudTrail management and data logs, and the new version that can ingest logs from the following AWS services by pulling them from an S3 bucket:

    • Amazon Virtual Private Cloud (VPC) - VPC Flow Logs
    • Amazon GuardDuty - Findings
    • AWS CloudTrail - Management and data events

    Architecture overview
    245793-image.png

    Additional Links:
    Find your Microsoft Sentinel data connector
    Connect Microsoft Sentinel to Azure, Windows, Microsoft, and Amazon services
    Creating Microsoft Sentinel custom connectors

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.