Forum Discussion
MDI Health Alerts - Send to Sentinel
There is no direct pipe for the health alerts to Sentinel.
As GershonLevitz-MSFT suggested in the Teams channel, you could use the syslog capability in MDI to get them into a server in your environment and then forward them to Sentinel using the log analytics agent. See Connect Syslog data to Microsoft Sentinel | Microsoft Learn
- Martin_SchvartzmanDec 18, 2022
Microsoft
Yes. Native forwarding the MDI health alerts to Sentinel is being evaluated.
- Dean_GrossJan 02, 2023Silver Contributor
FYI, for anyone else interested in this topic, an approach is described here https://cloudbrothers.info/en/integrate-mdi-health-alerts-microsoft-sentinel/
- DocyxNov 22, 2023Copper Contributor
Hi everyone
I created an analytics rule based on the Cloudbrother tutorial.
But the problem with this is that we cannot retrieve the name of the DC that has an issue. Is it possible to extract the content of the e-mails or something ?
I would like to be able to add the DC's name to the created incident.
My final goal is to send the health alerts, with the DC concerned into a Microsoft Teams discussion, so if there is an alternative or more direct way to do this I would be happy to know it.
Does anyone have any idea how to do this ?