Forum Discussion
yaniys04
Dec 19, 2020Copper Contributor
Raw logs data in sentinel
I have been exploring sentinel for quite some time now but I'm unable to figure out how to see the raw logs coming out from different sources. We can see it on different SIEM solutions like Qradar/sp...
GaryBushey
Dec 20, 2020Bronze Contributor
yaniys04 I do not believe the raw logs coming via Syslog or CEF are stored anywhere. You can write your queries to be able to see the information coming from individual machines as long as that information is being passed in.