Brings events into the WindowsEvent table of Microsoft Sentinel from a Windows Event Collector running AMA, rather than from every VM individually or into SecurityEvent.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Windows Forwarded Events in context, with comparison tables and the common traps.
Terms in this definition
- WindowsEvent
Where the Windows Forwarded Events connector lands its data in Log Analytics, Security log events included. Lots of built-in Sentinel rules read SecurityEvent, so they need adapting before they'll match it.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- WEC
Windows Event Forwarding subscriptions push events to this server's ForwardedEvents log, and from there AMA, through the Windows Forwarded Events connector, picks them up.
- Azure Monitor agent
Agent now used to collect logs from a machine's guest OS, driven by data collection rules; it took over from the Log Analytics agent (MMA).
- SecurityEvent
Table in Log Analytics containing Windows Security event log entries, gathered by Defender for Cloud or Microsoft Sentinel.