Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy
A security analyst is configuring data ingestion for Microsoft Sentinel. The analyst needs to connect Azure Activity logs from multiple subscriptions to a single Sentinel workspace. Which data connector should be used to achieve this efficiently?
- AAzure Firewall
- BAzure Activity
- CAzure Active Directory Identity Protection
- DMicrosoft 365 Defender
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Activity
The Azure Activity data connector is specifically designed to collect subscription-level events and audit logs from Azure, making it the correct choice for ingesting Azure Activity logs into Microsoft Sentinel.
Why the other options are wrong
- A. Azure Firewall is a product that generates its own logs, which would typically be ingested via a different connector, not the general Azure Activity logs.
- C. Azure Active Directory Identity Protection is used for identity-related risk detections, not general activity logs.
- D. Microsoft 365 Defender integrates security alerts and raw data from various Microsoft 365 services, not Azure subscription activity logs directly.
Azure Activity Data Connector
A Microsoft Sentinel data connector that ingests subscription-level events and audit logs from Azure into a Log Analytics workspace.
- Collects administrative, service health, resource health, and security events.
- Essential for monitoring operations within Azure subscriptions.
- Supports connecting multiple subscriptions to a single Sentinel instance.
Memory trick: Connectors are the 'pipes' that bring data into Sentinel's 'brain'.