Uses AMA and a DCR to send events from the Windows Security event log into Microsoft Sentinel's SecurityEvent table.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Windows Security Events via AMA in context, with comparison tables and the common traps.
Terms in this definition
- Azure Monitor agent
Agent now used to collect logs from a machine's guest OS, driven by data collection rules; it took over from the Log Analytics agent (MMA).
- Data collection rule
Rule in Azure Monitor specifying what the Azure Monitor Agent or Logs Ingestion API gathers (XPath event filters, for example), any transformation applied, and the destination.
- Event log
Two different things share the name. A Lakeflow pipeline writes one you can query for progress, lineage and data quality metrics; a compute resource has an Event log tab showing its lifecycle, for example resizing or losing spot nodes, kept for 60 days.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- SecurityEvent
Table in Log Analytics containing Windows Security event log entries, gathered by Defender for Cloud or Microsoft Sentinel.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
Related terms
- Security Events via Legacy Agent
An old Microsoft Sentinel connector, since retired, that relied on MMA (the Log Analytics agent) to bring in Windows security events. Its successor is Windows Security Events via AMA.