Forum Discussion
Dec 29, 2025
Ingesting Windows Security Events into Custom Datalake Tables Without Using Microsoft‑Prefixed Table
Hi everyone,
I’m looking to see whether there is a supported method to ingest Windows Security Events into custom Microsoft Sentinel Data Lake–tiered tables (for example, SecurityEvents_CL) without writing to or modifying the Microsoft‑prefixed analytical tables.
Essentially, I want to route these events directly into custom tables only, bypassing the default Microsoft‑managed tables entirely.
Has anyone implemented this, or is there a recommended approach?
Thanks in advance for any guidance.
Best Regards,
Prabhu Kiran
No RepliesBe the first to reply