Skip to content

Commit fe33617

Browse files
Merge pull request #264979 from yelevin/yelevin/ama-cef-fixes
Added What's New, updated screenshots
2 parents 314e17d + 7cad83f commit fe33617

9 files changed

+19
-4
lines changed

articles/sentinel/connect-dns-ama.md

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -117,13 +117,19 @@ To create filters:
117117

118118
:::image type="content" source="media/connect-dns-ama/windows-dns-ama-connector-create-filter.png" alt-text="Screenshot of creating a filter for the Windows D N S over A M A connector.":::
119119

120-
1. To add complex filters, select **Add field to filter** and add the relevant field.
120+
1. Choose the values for which you want to filter the field from among the values listed in the drop-down.
121121

122122
:::image type="content" source="media/connect-dns-ama/windows-dns-ama-connector-filter-fields.png" alt-text="Screenshot of adding fields to a filter for the Windows D N S over A M A connector.":::
123123

124-
1. To add new filters, select **Add new filters**.
125-
1. To edit, or delete existing filters or fields, select the edit or delete icons in the table under the **Configuration** area. To add fields or filters, select **Add data collection filters** again.
126-
1. To save and deploy the filters to your connectors, select **Apply changes**.
124+
1. To add complex filters, select **Add exclude field to filter** and add the relevant field. See examples in the [Use advanced filters](#use-advanced-filters) section below.
125+
126+
1. To add more new filters, select **Add new exclude filter**.
127+
128+
1. When finished adding filters, select **Add**.
129+
130+
1. Back on the main connector page, select **Apply changes** to save and deploy the filters to your connectors. To edit or delete existing filters or fields, select the edit or delete icons in the table under the **Configuration** area.
131+
132+
1. To add fields or filters after your initial deployment, select **Add data collection filters** again.
127133

128134
### Set up the connector with the API
129135

81.9 KB
Loading
32.3 KB
Loading
-12.7 KB
Loading
-7.04 KB
Loading
4.88 KB
Loading
25.3 KB
Loading
-64.6 KB
Loading

articles/sentinel/whats-new.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,9 @@ The listed features were released in the last three months. For information abou
2323

2424
## February 2024
2525

26+
- [AWS and GCP data connectors now support Azure Government clouds](#aws-and-gcp-data-connectors-now-support-azure-government-clouds)
27+
- [Windows DNS Events via AMA connector now generally available (GA)](#windows-dns-events-via-ama-connector-now-generally-available-ga)
28+
2629
### AWS and GCP data connectors now support Azure Government clouds
2730

2831
Microsoft Sentinel data connectors for Amazon Web Services (AWS) and Google Cloud Platform (GCP) now include supporting configurations to ingest data into workspaces in Azure Government clouds.
@@ -32,6 +35,12 @@ The configurations for these connectors for Azure Government customers differs s
3235
- [Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data](connect-aws.md)
3336
- [Ingest Google Cloud Platform log data into Microsoft Sentinel](connect-google-cloud-platform.md)
3437

38+
### Windows DNS Events via AMA connector now generally available (GA)
39+
40+
Windows DNS events can now be ingested to Microsoft Sentinel using the Azure Monitor Agent with the now generally available data connector. This connector allows you to define Data Collection Rules (DCRs) and powerful, complex filters so that you ingest only the specific DNS records and fields you need.
41+
42+
- For more information, see [Stream and filter data from Windows DNS servers with the AMA connector](connect-dns-ama.md).
43+
3544
## January 2024
3645

3746
### Reduce false positives for SAP systems with analytics rules

0 commit comments

Comments
 (0)