Forum Discussion

yaniys04's avatar
yaniys04
Copper Contributor
Dec 19, 2020

Raw logs data in sentinel

I have been exploring sentinel for quite some time now but I'm unable to figure out how to see the raw logs coming out from different sources. We can see it on different SIEM solutions like Qradar/splunk.

To explain better: I wanna see what logs have come in from a specific machine in last 1 hour.

1 Reply

  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor

    yaniys04 I do not believe the raw logs coming via Syslog or CEF are stored anywhere.  You can write your queries to be able to see the information coming from individual machines as long as that information is being passed in.

Resources