Forum Discussion

Pawel_Giza's avatar
Pawel_Giza
Copper Contributor
Oct 21, 2020

CEF logs CrowdStrike

Hi,

I imported logs from CrowdStrike to Azure Sentinel. I see a large number of logs but what can I do next?

I want to be able to search by hosts in Entity Behavior and check all activities by the host but at this moment Entity Behavior has only from Controllers Domain, how can I save logs from log analytics CEF CrowdStrike to Entity Behavior? 

 

  • Thijs Lecomte's avatar
    Thijs Lecomte
    Bronze Contributor
    I assume you mean UEBA?
    UEBA only supports a subset of data connectors as of now.

Resources