Microsoft Sentinel not ingesting logs from AWS Log Archive account

Milt 0 Reputation points
2025-12-17T22:54:09.6+00:00

I've followed all the steps necessary and double checked the configuration using this documentation: https://learn.microsoft.com/en-us/azure/sentinel/aws-s3-troubleshoot?source=recommendations

Followed steps for Microsoft Sentinel doesn’t receive data from the Amazon Web Services S3 connector or one of its data types

Are there any other resources or troubleshooting that could be done for this?

NOTE: The AWS Account ID I'm using for the trust policy is Microsoft Generic account ID found on Google, for commercial. AS when I reach out to our support for Azure, there seems to be no location from AzureAccountId; but in CloudFormation template Microsoft provides, it notes this,

AWS: !Sub "arn:${AWS::Partition}:iam::${SentinelAWSAccount}:root

In this case, what would be the AWS Account ID? IS this found in our Sentinel Service?

Microsoft Security | Microsoft Sentinel
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.