Microsoft Sentinel is a scalable, cloud-native, SIEM (security information event management) and SOAR (security orchestration automated response) platform. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response.
How to get data flowing
This integration is facilitated through the Cribl Stream Azure Monitor Logs Destination.
Enable Microsoft Sentinel’s integration with Azure Monitor Logs, ensuring appropriate permissions on the subscription that owns the Microsoft Sentinel workspace.
Configure Stream to send data to Azure Event Hubs via Destinations > Azure Monitor Logs.
Specify the Azure Log Analytics Workspace ID, Workspace Key, Log Type, backpressure behavior, and optional parameters.
Stream will start sending data as it becomes available.