Sentinel Integration - syslog

Vishal Dhatrak (Admin) 0 Reputation points
2024-02-28T07:49:51.84+00:00

Do we need to reactivate our defender for IoT sensors as online sensor when we wish to send syslog CEF UDP514 for sentinel integration?  Note: At present we have offline activated sensors.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
979 questions
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,371 Reputation points Microsoft Employee
    2024-02-28T20:36:35.9+00:00

    @Vishal Dhatrak (Admin)

    Thank you for your post!

    When it comes to connecting Microsoft Defender for IoT with Microsoft Sentinel in order to send your CEF and Syslog's, you'll need to re-activate your Defender for IoT Sensors.

    Tutorial: Connect Microsoft Defender for IoT with Microsoft Sentinel

    User's image

    Please note that you might also need to configure Sentinel to receive CEF and syslog messages. For more info.

    Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.

    0 comments No comments