@@ -218,6 +218,7 @@ Removing Microsoft Sentinel doesn't remove the Log Analytics workspace Microsoft
218
218
The following data sources are free with Microsoft Sentinel:
219
219
220
220
- Azure Activity Logs
221
+ - Microsoft Sentinel Health
221
222
- Office 365 Audit Logs, including all SharePoint activity, Exchange admin activity, and Teams
222
223
- Security alerts, including alerts from the following sources:
223
224
- Microsoft Defender XDR
@@ -236,7 +237,8 @@ The following table lists the data sources in Microsoft Sentinel and Log Analyti
236
237
237
238
| Microsoft Sentinel data connector | Free data type |
238
239
| -------------------------------------| --------------------------------|
239
- | ** Azure Activity Logs** | AzureActivity |
240
+ | ** Azure Activity Logs** | AzureActivity |
241
+ | ** Health monitoring for Microsoft Sentinel** <sup >[ 1] ( #audithealthnote ) </sup > | SentinelHealth |
240
242
| ** Microsoft Entra ID Protection** | SecurityAlert (IPC) |
241
243
| ** Office 365** | OfficeActivity (SharePoint) |
242
244
|| OfficeActivity (Exchange)|
@@ -249,6 +251,7 @@ The following table lists the data sources in Microsoft Sentinel and Log Analyti
249
251
| ** Microsoft Defender for Identity** | SecurityAlert (AATP) |
250
252
| ** Microsoft Defender for Cloud Apps** | SecurityAlert (Defender for Cloud Apps) |
251
253
254
+ <a id =" audithealthnote " >* <sup >1</sup >* </a > * For more information, see [ Auditing and health monitoring for Microsoft Sentinel] ( health-audit.md ) .*
252
255
253
256
For data connectors that include both free and paid data types, select which data types you want to enable.
254
257
0 commit comments