A security information and event management (SIEM) system is only as good as the data it receives. In Sentinel, data connectors bring logs from Microsoft services, other clouds, firewalls, servers and software-as-a-service (SaaS) apps into workspace tables. Connectors are delivered through Content hub, a catalog of solutions. A solution is a package that can include connectors, analytics rule templates, workbooks, hunting queries, parsers and playbooks for one product or scenario. You install the solution, then open its connector page (Configuration, Data connectors) and follow the steps it lists. Microsoft first-party sources, such as Microsoft Entra ID, Microsoft 365 and Defender XDR, usually connect with a few clicks because they are service-to-service. Servers need an agent. The Azure Monitor Agent (AMA) is the current agent for Windows and Linux; it replaced the older Log Analytics agent, which is retired. AMA is driven by data collection rules (DCRs), which define three things: the data sources to collect, an optional KQL transformation applied at ingestion time, and the destination workspace and table. One DCR can apply to many machines, and one machine can have several DCRs. Machines outside Azure are connected through Azure Arc so that AMA can be deployed to them.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.