Azure Activity Log Data Connector Configuration

Someiah C S 60 Reputation points
2024-05-20T08:13:54.5633333+00:00

Hi,

Recently, I onboarded Azure activity by following the instructions on the data connector page and completed the configuration successfully. This process involved creating a policy to send the logs to the log analytics workspace. During the setup, I selected the scope to include logs for a specific resource group as a test within the subscription. Although the policy has been created and is in a compliant state, I am not seeing any logs yet. Could you please assist me with this issue?

Thank you.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 35,196 Reputation points Microsoft Employee
    2024-05-21T00:03:03.1266667+00:00

    Hi @Someiah C S

    I would first recommend logging in as a Global Admin and disconnecting and re-enabling the data connector.

    Note that it can take about 10-20 minutes to create a new table in Log Analytics and for everything to synchronize. I would recommend verifying that you have new activity in those logs, since there might not be new data right away depending on the usage for your tenant.

    If the issue persists let me know and I am happy to further troubleshoot.

    If the information helped you, please Accept the answer. This will help us and improve searchability for others in the community who may be researching similar questions. Otherwise let me know if you still face the issue or have further questions.