Skip to content

Commit 265eda1

Browse files
committed
Tweaks
1 parent 3517516 commit 265eda1

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

articles/sentinel/data-connectors-reference.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1564,13 +1564,14 @@ Follow the instructions to obtain the credentials.
15641564
| --- | --- |
15651565
| **Data ingestion method** | **Azure service-to-service integration: <br>[Azure Monitor agent-based connections](connect-azure-windows-microsoft-services.md?tabs=AMA#windows-agent-based-connections)**<br><br>[Additional instructions for deploying the Windows Forwarded Events connector](#additional-instructions-for-deploying-the-windows-forwarded-events-connector) |
15661566
| **Prerequisites** | You must have Windows Event Collection (WEC) enabled and running.<br>Install the Azure Monitor Agent on the WEC machine. |
1567-
| **Log Analytics table(s)** | SecurityEvents |
1567+
| **xPath queries prefix** | "ForwardedEvents!*" |
1568+
| **Log Analytics table(s)** | WindowsEvents |
15681569
| **Supported by** | Microsoft |
15691570
| | |
15701571
15711572
### Additional instructions for deploying the Windows Forwarded Events connector
15721573
1573-
We recommend installing the [Advanced SIEM Information Model (ASIM)](normalization.md) parsers to ensure full support for data normalization. You can deploy these parsers from the [Azure Sentinel GitHub repository(link)] using the **Deploy** button in the **ASIM normalization support** section of the connector page.
1574+
We recommend installing the [Advanced SIEM Information Model (ASIM)](normalization.md) parsers to ensure full support for data normalization. You can deploy these parsers from the [Azure Sentinel GitHub repository](link) using the **Deploy** button in the **ASIM normalization support** section of the connector page.
15741575
15751576
## Windows Firewall
15761577
@@ -1586,6 +1587,7 @@ We recommend installing the [Advanced SIEM Information Model (ASIM)](normalizati
15861587
| Connector attribute | Description |
15871588
| --- | --- |
15881589
| **Data ingestion method** | **Azure service-to-service integration: <br>[Azure Monitor agent-based connections](connect-azure-windows-microsoft-services.md?tabs=AMA#windows-agent-based-connections)** |
1590+
| **xPath queries prefix** | "Security!*" |
15891591
| **Log Analytics table(s)** | SecurityEvents |
15901592
| **Supported by** | Microsoft |
15911593
| | |

0 commit comments

Comments
 (0)