Skip to content

Commit 510a58b

Browse files
authored
Merge pull request #183780 from yelevin/patch-1
Adding mention of tables besides Syslog for finding data
2 parents 953ac75 + e999876 commit 510a58b

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

articles/sentinel/connect-syslog.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,8 @@ All connectors listed in the gallery will display any specific instructions on t
103103

104104
1. To query the syslog log data in **Logs**, type `Syslog` in the query window.
105105

106+
(Some connectors using the Syslog mechanism might store their data in tables other than `Syslog`. Consult your connector's section in the [Microsoft Sentinel data connectors reference](data-connectors-reference.md) page.)
107+
106108
1. You can use the query parameters described in [Using functions in Azure Monitor log queries](../azure-monitor/logs/functions.md) to parse your Syslog messages. You can then save the query as a new Log Analytics function and use it as a new data type.
107109
108110
### Configure the Syslog connector for anomalous SSH login detection

0 commit comments

Comments
 (0)