Table in Log Analytics containing Windows Security event log entries, gathered by Defender for Cloud or Microsoft Sentinel.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SecurityEvent in context, with comparison tables and the common traps.
Terms in this definition
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Event log
Two different things share the name. A Lakeflow pipeline writes one you can query for progress, lineage and data quality metrics; a compute resource has an Event log tab showing its lifecycle, for example resizing or losing spot nodes, kept for 60 days.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
Related terms
- Windows Forwarded Events
Brings events into the WindowsEvent table of Microsoft Sentinel from a Windows Event Collector running AMA, rather than from every VM individually or into SecurityEvent.
- Windows Security Events connector
Brings Windows security events into the SecurityEvent table in Microsoft Sentinel. Onboarding servers to Defender for Cloud is not part of what it does.
- Windows Security Events via AMA
Uses AMA and a DCR to send events from the Windows Security event log into Microsoft Sentinel's SecurityEvent table.
- WindowsEvent
Where the Windows Forwarded Events connector lands its data in Log Analytics, Security log events included. Lots of built-in Sentinel rules read SecurityEvent, so they need adapting before they'll match it.