You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/data-connectors-reference.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1564,13 +1564,14 @@ Follow the instructions to obtain the credentials.
1564
1564
| --- | --- |
1565
1565
|**Data ingestion method**|**Azure service-to-service integration: <br>[Azure Monitor agent-based connections](connect-azure-windows-microsoft-services.md?tabs=AMA#windows-agent-based-connections)**<br><br>[Additional instructions for deploying the Windows Forwarded Events connector](#additional-instructions-for-deploying-the-windows-forwarded-events-connector) |
1566
1566
|**Prerequisites**| You must have Windows Event Collection (WEC) enabled and running.<br>Install the Azure Monitor Agent on the WEC machine. |
1567
-
|**Log Analytics table(s)**| SecurityEvents |
1567
+
|**xPath queries prefix**|"ForwardedEvents!*"|
1568
+
|**Log Analytics table(s)**| WindowsEvents |
1568
1569
|**Supported by**| Microsoft |
1569
1570
|||
1570
1571
1571
1572
### Additional instructions for deploying the Windows Forwarded Events connector
1572
1573
1573
-
We recommend installing the [Advanced SIEM Information Model (ASIM)](normalization.md) parsers to ensure full support fordata normalization. You can deploy these parsers from the [Azure Sentinel GitHub repository(link)] using the **Deploy** buttonin the **ASIM normalization support** section of the connector page.
1574
+
We recommend installing the [Advanced SIEM Information Model (ASIM)](normalization.md) parsers to ensure full support fordata normalization. You can deploy these parsers from the [Azure Sentinel GitHub repository](link) using the **Deploy** buttonin the **ASIM normalization support** section of the connector page.
1574
1575
1575
1576
## Windows Firewall
1576
1577
@@ -1586,6 +1587,7 @@ We recommend installing the [Advanced SIEM Information Model (ASIM)](normalizati
0 commit comments