Skip to content

Commit 91f13f8

Browse files
author
Jill Grant
authored
Merge pull request #277186 from cwatson-cat/patch-36
Sentinel connector - Update windows-firewall-events-via-ama.md
2 parents fec735d + 3b206b8 commit 91f13f8

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

articles/sentinel/data-connectors/windows-firewall-events-via-ama.md

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,15 +3,22 @@ title: "Windows Firewall Events via AMA (Preview) connector for Microsoft Sentin
33
description: "Learn how to install the connector Windows Firewall Events via AMA (Preview) to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 05/30/2024
6+
ms.date: 06/04/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
ms.collection: sentinel-data-connector
1010
---
1111

1212
# Windows Firewall Events via AMA (Preview) connector for Microsoft Sentinel
1313

14-
Windows Firewall is a Microsoft Windows application that filters information coming to your system from the internet and blocking potentially harmful programs. The firewall software blocks most programs from communicating through the firewall. Customers wishing to stream their Windows Firewall application logs collected from their machines can now use the AMA to stream those logs to the Microsoft Sentinel workspace. For more information, see the [Microsoft Sentinel documentation](https://go.microsoft.com/fwlink/p/?linkid=2228623&wt.mc_id=sentinel_dataconnectordocs_content_cnl_csasci).
14+
Windows Firewall is a Microsoft Windows application that filters information coming to your system from the internet and blocking potentially harmful programs. The firewall software blocks most programs from communicating through the firewall. To stream your Windows Firewall application logs collected from your machines, use the Azure Monitor agent (AMA) to stream those logs to the Microsoft Sentinel workspace.
15+
16+
A configured data collection endpoint (DCE) is required to be linked with the data collection rule (DCR) created for the AMA to collect logs. For this connector, a DCE is automatically created in the same region as the workspace. If you already use a DCE stored in the same region, it's possible to change the default created DCE and use your existing one through the API. DCEs can be located in your resources with **SentinelDCE** prefix in the resource name.
17+
18+
For more information, see the following articles:
19+
20+
- [Data collection endpoints in Azure Monitor](/azure/azure-monitor/essentials/data-collection-endpoint-overview)
21+
- [Microsoft Sentinel documentation](https://go.microsoft.com/fwlink/p/?linkid=2228623&wt.mc_id=sentinel_dataconnectordocs_content_cnl_csasci)
1522

1623
This is autogenerated content. For changes, contact the solution provider.
1724

0 commit comments

Comments
 (0)