Microsoft Sentinel

Learn how to send events to Azure Monitor to use with Microsoft Sentinel from Couchdrop

Requirements

Required Configuration

To connect to Azure Monitor you will need:

  • Azure Tenant ID

  • Azure Client ID

  • Azure Client Secret

  • Log Ingestion Endpoint

  • DCR Immutable ID

  • Stream Name

To learn how to setup Azure Monitor API access you can visit https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview

Configuration Steps

  1. Log in to Couchdrop and navigate to the Admin Panel - Logging

  2. Select Connect/Manage on the Microsoft Sentinel Provider Pill

  3. Select the Events to send to Azure Monitor

  4. Configure the required Azure Monitor fields

  5. Click Save Updates

Last updated

Was this helpful?