Forum Discussion
Dean_Gross
Dec 08, 2022Silver Contributor
MDI Health Alerts - Send to Sentinel
What is the best way to ensure that MDI health alerts like "Directory Services Advanced Auditing is not enabled" show as an alert in Sentinel?
Martin_Schvartzman
Microsoft
Dec 15, 2022There is no direct pipe for the health alerts to Sentinel.
As GershonLevitz-MSFT suggested in the Teams channel, you could use the syslog capability in MDI to get them into a server in your environment and then forward them to Sentinel using the log analytics agent. See Connect Syslog data to Microsoft Sentinel | Microsoft Learn
- Dean_GrossDec 15, 2022Silver ContributorThanks for the workaround, are there any plans to add this basic functionality? I don't think that we should have to do extra work like this after we have already configured the sensors and since the health data is already visible in M365 Security center
- Martin_SchvartzmanDec 18, 2022
Microsoft
Yes. Native forwarding the MDI health alerts to Sentinel is being evaluated.
- Dean_GrossJan 02, 2023Silver Contributor
FYI, for anyone else interested in this topic, an approach is described here https://cloudbrothers.info/en/integrate-mdi-health-alerts-microsoft-sentinel/