Windows Security Events via AMA connector for Microsoft Sentinel

You can stream all security events from the Windows machines connected to your Microsoft Sentinel workspace using the Windows agent. This connection enables you to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization’s network and improves your security operation capabilities. For more information, see the Microsoft Sentinel documentation.

Connector attributes

Connector attribute Description
Log Analytics table(s) SecurityEvent
Data collection rules support Azure Monitor Agent DCR
Supported by Microsoft Corporation

Next steps

For more information, go to the related solution in the Azure Marketplace.