Find your Microsoft Sentinel data connector
This article lists all supported, out-of-the-box data connectors and links to each connector's deployment steps.
Important
- Noted Microsoft Sentinel data connectors are currently in Preview. The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
- For connectors that use the Log Analytics agent, the agent will be retired on 31 August, 2024. If you are using the Log Analytics agent in your Microsoft Sentinel deployment, we recommend that you start planning your migration to the AMA. For more information, see AMA migration for Microsoft Sentinel.
Data connectors are available as part of the following offerings:
Solutions: Many data connectors are deployed as part of Microsoft Sentinel solution together with related content like analytics rules, workbooks and playbooks. For more information, see the Microsoft Sentinel solutions catalog.
Community connectors: More data connectors are provided by the Microsoft Sentinel community and can be found in the Azure Marketplace. Documentation for community data connectors is the responsibility of the organization that created the connector.
Custom connectors: If you have a data source that isn't listed or currently supported, you can also create your own, custom connector. For more information, see Resources for creating Microsoft Sentinel custom connectors.
Note
For information about feature availability in US Government clouds, see the Microsoft Sentinel tables in Cloud feature availability for US Government customers.
Data connector prerequisites
Each data connector will have its own set of prerequisites, such as required permissions on your Azure workspace, subscription, or policy, and so on, or other requirements for the partner data source you're connecting to.
Prerequisites for each data connector are listed on the relevant data connector page in Microsoft Sentinel, on the Instructions tab.
42Crunch
Abnormal Security Corporation
Akamai
AliCloud
Amazon Web Services
Apache
Apache Software Foundation
archTIS
ARGOS Cloud Security Pty Ltd
Arista Networks
Armorblox
Aruba
Atlassian
Auth0
Better Mobile Security Inc.
Bitglass
Blackberry
Bosch Global Software Technologies Pvt Ltd
Box
Broadcom
Cisco
- Cisco Application Centric Infrastructure
- Cisco ASA
- Cisco ASA/FTD via AMA (Preview)
- Cisco Duo Security (using Azure Functions)
- Cisco Identity Services Engine
- Cisco Meraki
- Cisco Secure Email Gateway
- Cisco Secure Endpoint (AMP) (using Azure Functions)
- Cisco Stealthwatch
- Cisco UCS
- Cisco Umbrella (using Azure Function)
- Cisco Web Security Appliance
Cisco Systems, Inc.
Citrix
Claroty
Cloud Software Group
Cloudflare
Cognni
CohesityDev
Contrast Security
Corelight Inc.
Crowdstrike
Cyber Defense Group B.V.
CyberArk
CyberPion
Cybersixgill
Cynerio
Darktrace
Defend Limited
Delinea Inc.
Derdack
Digital Guardian
Digital Shadows
Dynatrace
Elastic
Exabeam
ExtraHop Networks, Inc.
F5, Inc.
Fireeye
Flare Systems
Forescout
Fortinet
GitLab
- Google ApigeeX (using Azure Functions)
- Google Cloud Platform Cloud Monitoring (using Azure Functions)
- Google Cloud Platform DNS (using Azure Functions)
- Google Cloud Platform IAM (using Azure Functions)
- Google Workspace (G Suite) (using Azure Functions)
H.O.L.M. Security Sweden AB
iboss inc
Illumio
Illusive Networks
Imperva
Infoblox
Infoblox Inc.
Infosec Global
Insight VM / Rapid7
ISC
Island Technology Inc.
- Island Enterprise Browser Admin Audit (Polling CCP)
- Island Enterprise Browser User Activity (Polling CCP)
Ivanti
Jamf Software, LLC
Juniper
Kaspersky
Linux
Lookout, Inc.
- Lookout (using Azure Functions)
- Lookout Cloud Security for Microsoft Sentinel (using Azure Functions)
MarkLogic
McAfee
Microsoft
- Automated Logic WebCTRL
- Azure Active Directory
- Azure Active Directory Identity Protection
- Azure Activity
- Azure Batch Account
- Azure Cognitive Search
- Azure Data Lake Storage Gen1
- Azure DDoS Protection
- Azure Event Hub
- Azure Key Vault
- Azure Kubernetes Service (AKS)
- Azure Logic Apps
- Azure Service Bus
- Azure Storage Account
- Azure Stream Analytics
- Azure Web Application Firewall (WAF)
- Common Event Format (CEF)
- Common Event Format (CEF) via AMA
- DNS
- Fortinet FortiWeb Web Application Firewall
- Microsoft 365 (formerly, Office 365)
- Microsoft 365 Defender
- Microsoft 365 Insider Risk Management
- Microsoft Defender for Cloud
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for IoT
- Microsoft Defender for Office 365
- Microsoft Defender Threat Intelligence
- Microsoft PowerBI
- Microsoft Project
- Microsoft Purview (Preview)
- Microsoft Purview Information Protection
- Network Security Groups
- Security Events via Legacy Agent
- Syslog
- Threat intelligence - TAXII
- Threat Intelligence Platforms
- Threat Intelligence Upload Indicators API (Preview)
- Windows DNS Events via AMA (Preview)
- Windows Firewall
- Windows Forwarded Events
- Windows Security Events via AMA
Microsoft Corporation
Microsoft Corporation - sentinel4github
Microsoft Sentinel Community, Microsoft Corporation
- Exchange Security Insights Online Collector (using Azure Functions)
- Forcepoint CASB
- Forcepoint CSG
- Forcepoint DLP
- Forcepoint NGFW
- MISP2Sentinel
MongoDB
Morphisec
MuleSoft
Nasuni Corporation
NetClean Technologies AB
Netskope
Netwrix
Nginx
Noname Gate, Inc.
Nozomi Networks
NXLog Ltd.
Okta
OneLogin
OpenVPN
Oracle
Orca Security, Inc.
OSSEC
Palo Alto Networks
- Palo Alto Networks (Firewall)
- Palo Alto Networks Cortex Data Lake (CDL)
- Palo Alto Prisma Cloud CSPM (using Azure Functions)
Perimeter 81
Ping Identity
PostgreSQL
Proofpoint
Pulse Secure
Qualys
- Qualys VM KnowledgeBase (using Azure Functions)
- Qualys Vulnerability Management (using Azure Functions)
RedHat
RSA
Rubrik, Inc.
SailPoint
Salesforce
Secure Practice
SecurityBridge
Senserva, LLC
SentinelOne
Slack
Snowflake
SonicWall Inc
Sonrai Security
Sophos
Squid
Symantec
- Symantec Endpoint Protection
- Symantec Integrated Cyber Defense Exchange
- Symantec ProxySG
- Symantec VIP
TALON CYBER SECURITY LTD
Tenable
The Collective Consulting BV
TheHive
Theom, Inc.
Trend Micro
TrendMicro
Ubiquiti
vArmour Networks
Vectra AI, Inc
VMware
WatchGuard Technologies
WireX Systems
WithSecure
ZERO NETWORKS LTD
Zimperium, Inc.
Zoom
Zscaler
Next steps
For more information, see:
Feedback
Submit and view feedback for