Blog Post

Microsoft Sentinel Blog
12 MIN READ

Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)

Ofer_Shezaf's avatar
Ofer_Shezaf
Icon for Microsoft rankMicrosoft
Aug 14, 2019

(Last updated Apr 20th, 2021)

 

Please note that as the built-in list of connectors in Azure Sentinel is growing, this list is not actively maintained anymore. Refer to the Azure Sentinel connector documentation for more information. 

 

Source types

 

Built-in

Built-in connectors are included in the Azure Sentinel documentation and the data connectors pane in the product itself. Those connectors are based on one of the technologies listed below. Therefore a built-in connector will have a type: CEF, Syslog, Direct, and so forth.

 

Syslog and CEF

Most network and security systems support either Syslog or CEF (which stands for Common Event Format) over Syslog as means for sending data to a SIEM. This makes Syslog or CEF the most straightforward ways to stream security and networking events to Azure Sentinel.

 

  • Want to learn more about best practices for CEF collection? see here.
  • Want to scale CEF or Syslog collection?  Use a VM scale set as described here.

 

The advantage of CEF over Syslog is that it ensures the data is normalized, making it more immediately useful for analysis using Sentinel. However, unlike many other SIEM products, Sentinel allows ingesting unparsed Syslog events and performing analytics on them using query time parsing. 

 

The number of systems supporting Syslog or CEF is in the hundreds, making the table below by no means comprehensive. We will update this list continuously. The table provides links to the source device's vendor documentation for configuring the device to send events in Syslog or CEF.

 

Tip: Want to ingest test CEF data? here is how to do that.

 

Direct

Most Microsoft cloud sources and many other clouds and on-prem systems can send to Azure Sentinel natively. For Microsoft Azure sources, this often uses their diagnostics feature, on which you can read more here.

 

Agent

The Log Analytics agent can collect different types of events from servers and endpoints listed here. To learn more about the agent, read Azure Sentinel Agent: Collecting telemetry from on-prem and IaaS server.

 

Threat Intelligence (TI)

You can use one of the threat intelligence connectors:

  • Platform, which uses the Graph Security API
  • TAXII, which uses the TAXII 2.0 protocol

to ingest threat intelligence indicators, which are used by Azure Sentinel's built-in TI analytics rules, and to build your own rules. You can read more about the Threat Intelligence connectors in module #6 of the Azure Sentinel Ninja Training 

 

Custom: Logic Apps, Logstash, Azure Functions, and others

In addition to CEF and Syslog, many solutions are based on Sentinel's data collector API and create custom log tables in the workspace. Those belong to 3 groups:

  • Sources that support Logstash, which in turn has an output plug-in that can send the events to Azure Sentinel.
  • Sources that have native support for the API.
  • Sources for which there is a community or Microsoft field created solution that uses the API, usually using Logic Apps or an Azure function.

You can read more about custom connectors here.

 

Automation and integration

While all the types above focused on getting telemetry into Azure Sentinel, connectors marked as automation/integration enable Azure Sentinel to implement other use cases such as sending information to another system or performing an action on another system. Those might be API-based on integration or Logic App-based integrations. 

 

The Grand List

 

Vendor

Product

Connector
Type

Connecting and using

Agari Phishing Defense and Brand Protection Built-in (Function, Graph Security API) Instructions
AI Vectra Detect Built-in (CEF) Instructions
Akamai   Built-in (CEF) Instructions

Alcide

kAudit

Built-in (API)

Instructions

AlgoSec

ASMS

CEF

Instructions and examples

Anomali

Limo

Built-in (TAXII)

Instructions

Anomali

ThreatStream

Built-in (TI Platform)

Instructions

Anomali

Match

Integration

Overview and instructions

Apache

httpd

Built-in (Agent custom logs)

Instructions

Also, read using rsyslog or logger as a file forwarder for an alternative method.

Apache

Kafka

Logstash

See Logstash plug-in. Use to get events sent using Kafka, not for Kafka's own audit events.

Aruba

ClearPass

CEF

Instructions

AT&T Cyber

AlienVault OTX

TI (Platform)

Using Logic Apps, See instructions

AWS

CloudTrail

Built-in

Sentinel built-in connector

AWS

CloudTrail S3 logs

Custom

Using an Azure Function. See here.

Using an AWS Lambda Function. See here.

AWS

CloudWatch

Logstash

See Logstash Plug-in.

AWS

Kinesis

Logstash

See Logstash Plug-in.

AWS

Object Level S3 Logging

Logstash 

See here.

AWS

Security Hub

Custom

Azure Function. See here.

Barracuda

WAF

Built-in (API)

Instructions

Barracuda

CloudGen Firewall

API

Sentinel built-in connector

BETTER Mobile

Threat Defense

Built-in (API)

Instructions

Beyond Security

beSECURE

Built-in (API)

Instructions

Carbon Black

Cloud Endpoint Standard (Cb Defense)

Built-in (Function)

Syslog

Sentinel built-in connector 

 

Instructions

Carbon Black

(Cb Response)

Syslog

Instructions

Checkpoint   CEF

Sentinel Built-in connector

Cisco ACS Syslog

Instructions

Cisco ASA Cisco (CEF)

Sentinel built-in connector

Notes:

- Cisco ASA support uses Sentinel's CEF pipeline. However, Cisco's logging is not in CEF format.

- Make sure you disable logging timestamp using "no logging timestamp". See here for more details.

Cisco Cloud Security Gateway (CWS) CEF Use the Cisco Advanced Web Security Reporting.
Cisco FTD Cisco (CEF) FTP Platform logs are compatible with ASA logs and can use the same connector (see here).
Cisco IOS Syslog Instructions
Cisco ISE  (NAC) Syslog Instructions
Cisco Web Security Appliance (WSA) CEF Use the Cisco Advanced Web Security Reporting.

Cisco

Meraki

Syslog

Instructions

Event Types and Log Samples

Cisco eStreamer CEF

Using enCore

Cisco Firepower Threat Defense

CEF

Syslog

Using eStreamer enCore

Instructions, Event reference

Cisco FireSight

CEF

Using eStreamer enCore

Cisco IronPort Web Security Appliance Syslog

Instructions

Cisco Nexus Syslog

Instructions

Cisco Umbrella Built-in (Function)

Instructions

Also, see this blog post

for a custom solution

Cisco Unified Computing System (UCS) Built-in (Syslog)

Instructions

Cisco Viptela SD-WAN Syslog

Instructions

Citrix Analytics Built-in (Direct)

Instructions

Citrix NetScaler  Syslog

Instructions

Message format

Citrix NetScaler App FW Built-in (CEF) Instructions

Clearswift

Web Security Gateway

Syslog

Instructions

Cloudflare

 

 

Use Cloudflare Logpush to send to storage and a custom connector to read events from storage (for example, reading AWS S3 buckets).

Cribl

LogStream

Direct

Instructions

CrowdStrike

Falcon

CEF

Instructions. Use a SIEM connector installed on-premises.

CyberArk

Endpoint Privilege Manager (EPM)

Syslog

Logstash

Instructions (for both)

CyberArk

Privileged Access Security (PTA)

CEF

Instructions

Message format

Darktrace

Immune

CEF

See announcement. Contact vendor for instructions.

Digital Guardian

 

CEF

3rd party instructions

DocuSign

Monitor

Custom

See this blog post

Duo Security

 

CEF

Using Duo LogSync

Extrahop

Reveal

Built-in (CEF)

Instructions

F5

ASM (WAF)

Built-in (CEF)

Instructions

F5

BigIP (System, LTM, AFM, ASM, APM, AVR)

Built-in (Direct)

Instructions 

Fastly

WAF Custom

See this blog post (Logic Apps or Azure Function)

Forcepoint

Web Security (WebSense) CEF

Instructions

Detailed reference

Forcepoint

CASB CEF

Sentinel built-in connector

Forcepoint

DLP Direct

Sentinel built-in connector

Forcepoint

NGFW CEF

Sentinel built-in connector

Forescout

CounterAct CEF

Instructions

Fortinet

  CEF

Sentinel built-in connector

Log message reference

CEF mapping and examples

Fortinet

FortiSIEM

CEF

Instructions

Fortinet

FortiSOAR

Integration

Instructions

GitHub

 

Custom

See connector, rules, and hunting queries 

here

GCP

Cloud Storage

Logstash

See Plug-in. Use to get events stored in GCP Cloud Storage, not for Cloud Storage own audit events.

GCP

Pub/Sub

Logstash

See Plug-in. Use to get events sent using Pub/Sub, not for Pub/Sub own audit events.

GCP

Stacdriver

Logstash

 

Custom

Through GCP Cloud Storage or GCP Pub/Sub as described above. 

Using GCP Cloud Function. See here.

Group-IB

 

Custom (TI Platform)

Using Logic Apps. See instructions

GuardiCore

Centra

CEF

Contact vendor for instructions

HP

Printers

Syslog

Instructions

IBM

iSeries

CEF

See here.

IBM

QRadar events

Syslog

Forward raw events or correlation events in raw, parsed, or JSON format. See instructions.

IBM

QRadar offenses

Custom (Function)

Blog post

IBM

X-Force

TI (TAXII)

Instructions

IBM

zSecure

CEF

See What's new for zSecure V2.3.0

Note that it supports alerts only.

Illusive 

Attack Management System

Syslog

Sentinel built-in connector

Imperva

SecureSphere

CEF

Instructions

Infoblox NIOS

Built-in (Syslog)

Instructions

InSights  

TI (TAXII)

TAXII Instructions and related workbook

Jamf Pro

Syslog

Instructions

Juniper ATP

CEF

Instructions

Juniper JunOS based devices

Built-in (Syslog)

Instructions

Kaspersky Security Center  CEF Instructions

ManageEngine

AD Audit Plus

CEF

Instructions (use ArcSight instructions)

ManageEngine

Exchange Reporter Plus

Syslog

Instructions

McAfee

ePO

Syslog

Instructions (Note: TLS only (requires rsyslog TLS configuration)

McAfee

MVISION EDR

Syslog

Instructions

McAfee

Web Gateway

CEF

Instructions

Microfocus

Fortify AppDefender

CEF

Instructions (require authentication; contact vendor for further details).

Microsoft

Active Directory

Agent

Most AD events are logged as part of security events. 

Also, See in this list:

  • LDAP auditing
  • SMBv1 auditing

Microsoft

Advanced Threat Protection (ATA)

CEF

Microsoft

Azure Active Directory (AAD)

Built-in (Diagnostics)

Microsoft

Azure Active Directory Domain Services

Diagnostics

Microsoft

Azure Active Directory Identity Protection

 

Microsoft

Azure

Azure Activity

Azure Subscriptions

Azure Management Groups

Direct

Microsoft

Application Insights

Direct

Microsoft

App Services & Web Application monitoring 

Direct

Instructions and reference architecture 

Microsoft

Azure B2B

Direct

Included as part of AAD events

Microsoft

Azure B2C

Direct

collect B2C logs from your B2C tenant to your primary tenant AAD logs as described here

Microsoft

Azure Cosmos DB

Direct

Instructions

Microsoft

Azure Data Lake Gen 1

Direct

Microsoft

Azure Data Factory

Direct

Instructions

Microsoft

Azure Databricks

Direct

Instructions

Microsoft

Azure DDOS

Built-in (diagnostics)

Microsoft Azure Defender  and Azure Security Center (ASC)

Direct

Microsoft

Azure Defender for IoT

Built-in (Direct)

Microsoft

Azure DevOps

Direct

Instructions

Microsoft

Azure Event Hub (subscription)

Logstash

See Logstash Plug-in. Use to get events sent using an Event Hub, not for Event Hub own audit events.

Microsoft

Azure Files

Direct (Diagnostics)

Instructions

Schema information

Microsoft

Azure Firewall

Built-in (diagnostics)

Microsoft

Azure Front Door

Direct

Instructions
Microsoft Azure Key Vault (AKV)

Built-in (Diagnostics)

Connect:

Use:

Microsoft Azure Information Protection (Classic and Unified Labeling)

Built-in (Direct)

Instructions
Microsoft Azure Kubernetes Service (AKS)

Direct

Microsoft Azure Log Analytics

Direct

Collect query auditing and other metrics: Instructions
Microsoft Azure Logic Apps

Direct

Instructions
Microsoft Azure Network Security Groups (NSG)

Direct

Microsoft Azure SQL

Built-in (diagnostics)

Microsoft Azure SQL Managed Instance

Direct

Instructions
Microsoft Azure Site Recovery

Direct

Instructions
Microsoft Azure Storage

Direct

Instructions

Blog: Blob and File Storage Investigations

Microsoft Azure Storage Content

Custom (Azure Function)

Ingest the content of Azure Storage Blobs. See GitHub.
Microsoft Azure Synapse

Direct

Instructions
Microsoft Azure Web Application Firewall (WAF)

Built-in (Diagnostics)

Microsoft

BitLocker / MBAM

Agent

Using Windows Event collection. Blog post

Microsoft

Cloud App Security (Alerts, Discovery logs)

Built-in (Direct)

Microsoft

Cloud App Security (Activity Log)

CEF

Instructions

Microsoft

Defender for Office

Built-in

Custom

 

 

 

For AIRs alerts: instructions

For other alerts: Use Either a Logic App or an Azure function custom connector. For the Azure Function connector, query for RecordType_d == "28", "41" or "47" .

Microsoft

Defender for Identity (Azure ATP) Alerts

Built-in

Microsoft

Defender for Identity (Azure ATP) Events

CEF

Microsoft

Desktop Analytics

Direct

Connect

Microsoft

DNS

Agent

Sentinel built-in connector

Microsoft

Dynamics 365

Built-in

Sentinel built-in connector

Microsoft

Dynamics (not 365)

Agent

Using IIS logs

Using Dynamics Trace Files

Microsoft

IIS

Agent

Instructions

Microsoft

Intune

Direct

Connect

Use cases

Microsoft

LDAP (Windows Server)

Agent

Configure AD diagnostics logging and set "16 LDAP Interface Events" to 2 or above.

Microsoft

Office 365 (Exchange, SharePoint, OneDrive, DLP Alerts)

Built-in

 

Sentinel built-in connector

For details about DLP alerts, read here

Microsoft 

Office 365 (Microsoft Defender for Office; formerly Office ATP, PowerBI, Yammer, Sway, Forms, eDiscovery, and others)

Custom (Azure Function, Logic Apps)

Use Either a Logic App or an Azure function custom connector

Microsoft

Office 365 e-mail trace logs

Custom (Logic Apps)

See Blog Post.

Microsoft

PowerBI Embedded

Direct (Diagnostics)

Instructions

Microsoft

SMBv1 (Windows Server)

Agent

See Enable Auditing on SMB Servers, and the CmdLet reference 

Microsoft

Teams (Call Logs)

Custom

Using Logic Apps

Microsoft

Teams (Management Activity)

Built-in

Microsoft

Teams Shifts

Custom

Use Either a Logic App or an Azure function custom connector. For the Azure Function connector, query for RecordType_d == "73"

Microsoft

SCCM

Agent

Instructions

Microsoft

SQL Server

Agent

Instructions, parser, rules, and hunting queries

You can also audit at the engine level.

Microsoft

Sysmon

Agent

Using Windows Event collection. Blog post

Microsoft

Windows (Security Events)

Agent

Microsoft

Windows (Other Events, Sysmon)

Agent

Instructions

Microsoft

Windows network connections

Agent

VM Insights

Wire Data

Microsoft

Windows Firewall

Agent

Sentinel built-in connector

Microsoft

Windows Virtual Desktop

Direct

Mimecast

 

Agent

Announcement. For technical instructions, contact the vendor.

Minerva Labs

 

CEF

Please ask the vendor for instructions.

MISP

 

TI (Platform)

Sentinel built-in connector

NetApp

ONTAP

Syslog

Instructions

Note that those are management activity audit logs and not file usage activity logs.

Netflow

 

Logstash

Use the Netflow codec plug-in

Nexthink

 

CEF

Instructions

Nozomi

Guardian

CEF

Contact vendor for details

NXlog

 

Direct

Instructions

Okta

SSO

Built-in (Function)

Instructions

One Identity

Safeguard

Built-in (CEF)

Instructions

Oracle

Cloud (OCI)

Custom (Azure Function)

Available Here

Oracle

DB

Syslog

Instructions

Orca

 

Built-in (API)

Instructions

OSSEC

 

CEF

Instructions

Pager Duty

 

Automation (Playbook)

Blog post

Palo Alto

Cloudgenix

Syslog

Instructions

Palo Alto

Minemeld

TI (Platform)

Sentinel built-in connector

Palo Alto

PanOS

CEF

Sentinel built-in connector

Palo Alto

Panorama

CEF

Instructions

Palo Alto

Prisma

Syslog

Custom

Instructions, Fields

Logic Apps using a Webhook and clarification

Palo Alto

Traps through Cortex

Syslog

Instructions

Notes:

- Require rsyslog configuration to support RFC5424

- TLS only (requires rsyslog TLS configuration)

- The certificate has to be signed by a public CA

Palo Alto

XDR

CEF

Instructions

Palo Alto

XSOAR

Integration

Forward Azure Sentinel incidents to Palo Alto XSOAR 

Perimeter 81

 

Built-in (API)

Instructions

Ping Identity

Federate

CEF

Instructions

Ping Identity

Provisioner

CEF

Instructions

Postgress DB Syslog, Windows Event log

Instructions

Proofpoint On Demand Built-in (API)

Instructions

Proofpoint TAP Built-in (Function)

Instructions

Pulse Connect Built-in (Syslog)

Instructions

Qualys VM Built-in (Function)

Instructions

Radware Cloud WAF Logstash

Instructions

RedHat OpenShift Syslog
API

Instructions for Syslog
Fluentd Log Analytics plugin for API

RedHat Azure OpenShift Syslog
Custom

Instructions for Syslog
Fluentd Log Analytics plugin for API

RiskIQ   Action (Logic Apps)

Azure Logic-Apps built-in connector

Salesforce Service Cloud Built-in (Function)

Instructions

SAP Hana Syslog

Instructions (requires an SAP account)

SentinelOne   CEF

Please consult the vendor for instructions

SNMP   Syslog

Instructions

Snort   Agent

Instructions

SonicWall   CEF

Instructions

Make sure you:
- Select local use 4 as the facility.

- Select ArcSight as the Syslog format.

Sophos Central CEF Instructions. Note that the script provided by Sophos has to be scheduled using a cron job, which is not documented on the reference page.
Sophos XF Firewall Built-in (Syslog) Instructions
Squadra  secRMM Built-in (API) Instructions
Squid Proxy  

Built-in (Agent)

Syslog

Instructions

 

Configure access logs with either the TCP or UDP modules. Sentinel's built-in queries use the default log format.

Symantec

DLP

Syslog

CEF

Instructions. Note that only UDP is supported

Instructions. Uses response automation.

Symantec

ICDX

Built-in (API)

Instructions

Symantec

Proxy SG (Bluecoat)

Built-in (Syslog)

Instructions

Symantec   Endpoint Protection Manager Syslog Instructions  
Symantec Cloud Workload Protection API Instructions
Symantec VIP Built-in (Syslog) Instructions
TheHive  

Integration

Send new incidents to TheHive

Thinkst Canary

Syslog

Instructions

ThreatConnect  

TI (Platform)

Sentinel built-in connector

ThreatQuotient  

TI (Platform)

Sentinel built-in connector

Thycotic Secret Server

CEF

Instructions

TitanHQ WebTitan Cloud

Syslog

Instructions

Trend Micro  

CEF

Using Control Manager

Using LogForwarder

Trend Micro Apax Central (Cloud and On-prem)

CEF

Instructions

Trend Micro Deep Security

CEF

Sentinel built-in connector

Tufin SecureTrack

Syslog

Instructions

Varonis

DatAlert

CEF

Instructions

WatchGuard   CEF Instructions
Zimperium  
Mobile Threat Defense Built-in (API) Instructions 
zScaler Internet Access (ZIA) Built-in (CEF) Instructions
zScaler Private Access (ZPA) Logstash Use LSS. Since LSS sends raw TCP but not Syslog, you will have to use Logstash and not Azure Sentinel's native connector. 
Zoom   Custom Using Azure Function. See blog post.

 

Updated Sep 30, 2021
Version 171.0

78 Comments

"}},"componentScriptGroups({\"componentId\":\"custom.widget.Social_Sharing\"})":{"__typename":"ComponentScriptGroups","scriptGroups":{"__typename":"ComponentScriptGroupsDefinition","afterInteractive":{"__typename":"PageScriptGroupDefinition","group":"AFTER_INTERACTIVE","scriptIds":[]},"lazyOnLoad":{"__typename":"PageScriptGroupDefinition","group":"LAZY_ON_LOAD","scriptIds":[]}},"componentScripts":[]},"component({\"componentId\":\"custom.widget.MicrosoftFooter\"})":{"__typename":"Component","render({\"context\":{\"component\":{\"entities\":[],\"props\":{}},\"page\":{\"entities\":[\"board:MicrosoftSentinelBlog\",\"message:803891\"],\"name\":\"BlogMessagePage\",\"props\":{},\"url\":\"https://techcommunity.microsoft.com/blog/microsoftsentinelblog/azure-sentinel-the-connectors-grand-cef-syslog-direct-agent-custom-and-more/803891\"}}})":{"__typename":"ComponentRenderResult","html":"
"}},"componentScriptGroups({\"componentId\":\"custom.widget.MicrosoftFooter\"})":{"__typename":"ComponentScriptGroups","scriptGroups":{"__typename":"ComponentScriptGroupsDefinition","afterInteractive":{"__typename":"PageScriptGroupDefinition","group":"AFTER_INTERACTIVE","scriptIds":[]},"lazyOnLoad":{"__typename":"PageScriptGroupDefinition","group":"LAZY_ON_LOAD","scriptIds":[]}},"componentScripts":[]},"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/community/NavbarDropdownToggle\"]})":[{"__ref":"CachedAsset:text:en_US-components/community/NavbarDropdownToggle-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/common/QueryHandler\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/common/QueryHandler-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageCoverImage\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageCoverImage-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/nodes/NodeTitle\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/nodes/NodeTitle-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageTimeToRead\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageTimeToRead-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageSubject\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageSubject-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/users/UserLink\"]})":[{"__ref":"CachedAsset:text:en_US-components/users/UserLink-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/users/UserRank\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/users/UserRank-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageTime\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageTime-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageBody\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageBody-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageCustomFields\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageCustomFields-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageRevision\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageRevision-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageReplyButton\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageReplyButton-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/messages/MessageAuthorBio\"]})":[{"__ref":"CachedAsset:text:en_US-components/messages/MessageAuthorBio-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/users/UserAvatar\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/users/UserAvatar-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/ranks/UserRankLabel\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/ranks/UserRankLabel-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/users/UserRegistrationDate\"]})":[{"__ref":"CachedAsset:text:en_US-components/users/UserRegistrationDate-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/nodes/NodeAvatar\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/nodes/NodeAvatar-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/nodes/NodeDescription\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/nodes/NodeDescription-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/common/Pager/PagerLoadMorePreviousNextLinkable\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/common/Pager/PagerLoadMorePreviousNextLinkable-1744658876102"}],"message({\"id\":\"message:2527916\"})":{"__ref":"BlogReplyMessage:message:2527916"},"message({\"id\":\"message:2469587\"})":{"__ref":"BlogReplyMessage:message:2469587"},"message({\"id\":\"message:2366737\"})":{"__ref":"BlogReplyMessage:message:2366737"},"message({\"id\":\"message:2321857\"})":{"__ref":"BlogReplyMessage:message:2321857"},"message({\"id\":\"message:2321630\"})":{"__ref":"BlogReplyMessage:message:2321630"},"message({\"id\":\"message:3779691\"})":{"__ref":"BlogReplyMessage:message:3779691"},"message({\"id\":\"message:3440417\"})":{"__ref":"BlogReplyMessage:message:3440417"},"message({\"id\":\"message:2795218\"})":{"__ref":"BlogReplyMessage:message:2795218"},"message({\"id\":\"message:2794006\"})":{"__ref":"BlogReplyMessage:message:2794006"},"message({\"id\":\"message:2641553\"})":{"__ref":"BlogReplyMessage:message:2641553"},"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"components/tags/TagView/TagViewChip\"]})":[{"__ref":"CachedAsset:text:en_US-components/tags/TagView/TagViewChip-1744658876102"}],"cachedText({\"lastModified\":\"1744658876102\",\"locale\":\"en-US\",\"namespaces\":[\"shared/client/components/nodes/NodeIcon\"]})":[{"__ref":"CachedAsset:text:en_US-shared/client/components/nodes/NodeIcon-1744658876102"}]},"CachedAsset:pages-1744410786543":{"__typename":"CachedAsset","id":"pages-1744410786543","value":[{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"BlogViewAllPostsPage","type":"BLOG","urlPath":"/category/:categoryId/blog/:boardId/all-posts/(/:after|/:before)?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CasePortalPage","type":"CASE_PORTAL","urlPath":"/caseportal","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CreateGroupHubPage","type":"GROUP_HUB","urlPath":"/groups/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CaseViewPage","type":"CASE_DETAILS","urlPath":"/case/:caseId/:caseNumber","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"InboxPage","type":"COMMUNITY","urlPath":"/inbox","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"HelpFAQPage","type":"COMMUNITY","urlPath":"/help","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"IdeaMessagePage","type":"IDEA_POST","urlPath":"/idea/:boardId/:messageSubject/:messageId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"IdeaViewAllIdeasPage","type":"IDEA","urlPath":"/category/:categoryId/ideas/:boardId/all-ideas/(/:after|/:before)?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"LoginPage","type":"USER","urlPath":"/signin","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"BlogPostPage","type":"BLOG","urlPath":"/category/:categoryId/blogs/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"UserBlogPermissions.Page","type":"COMMUNITY","urlPath":"/c/user-blog-permissions/page","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ThemeEditorPage","type":"COMMUNITY","urlPath":"/designer/themes","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TkbViewAllArticlesPage","type":"TKB","urlPath":"/category/:categoryId/kb/:boardId/all-articles/(/:after|/:before)?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1730142000000,"localOverride":null,"page":{"id":"AllEvents","type":"CUSTOM","urlPath":"/Events","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"OccasionEditPage","type":"EVENT","urlPath":"/event/:boardId/:messageSubject/:messageId/edit","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"OAuthAuthorizationAllowPage","type":"USER","urlPath":"/auth/authorize/allow","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"PageEditorPage","type":"COMMUNITY","urlPath":"/designer/pages","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"PostPage","type":"COMMUNITY","urlPath":"/category/:categoryId/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForumBoardPage","type":"FORUM","urlPath":"/category/:categoryId/discussions/:boardId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TkbBoardPage","type":"TKB","urlPath":"/category/:categoryId/kb/:boardId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"EventPostPage","type":"EVENT","urlPath":"/category/:categoryId/events/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"UserBadgesPage","type":"COMMUNITY","urlPath":"/users/:login/:userId/badges","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"GroupHubMembershipAction","type":"GROUP_HUB","urlPath":"/membership/join/:nodeId/:membershipType","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"MaintenancePage","type":"COMMUNITY","urlPath":"/maintenance","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"IdeaReplyPage","type":"IDEA_REPLY","urlPath":"/idea/:boardId/:messageSubject/:messageId/comments/:replyId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"UserSettingsPage","type":"USER","urlPath":"/mysettings/:userSettingsTab","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"GroupHubsPage","type":"GROUP_HUB","urlPath":"/groups","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForumPostPage","type":"FORUM","urlPath":"/category/:categoryId/discussions/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"OccasionRsvpActionPage","type":"OCCASION","urlPath":"/event/:boardId/:messageSubject/:messageId/rsvp/:responseType","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"VerifyUserEmailPage","type":"USER","urlPath":"/verifyemail/:userId/:verifyEmailToken","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"AllOccasionsPage","type":"OCCASION","urlPath":"/category/:categoryId/events/:boardId/all-events/(/:after|/:before)?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"EventBoardPage","type":"EVENT","urlPath":"/category/:categoryId/events/:boardId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TkbReplyPage","type":"TKB_REPLY","urlPath":"/kb/:boardId/:messageSubject/:messageId/comments/:replyId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"IdeaBoardPage","type":"IDEA","urlPath":"/category/:categoryId/ideas/:boardId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CommunityGuideLinesPage","type":"COMMUNITY","urlPath":"/communityguidelines","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CaseCreatePage","type":"SALESFORCE_CASE_CREATION","urlPath":"/caseportal/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TkbEditPage","type":"TKB","urlPath":"/kb/:boardId/:messageSubject/:messageId/edit","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForgotPasswordPage","type":"USER","urlPath":"/forgotpassword","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"IdeaEditPage","type":"IDEA","urlPath":"/idea/:boardId/:messageSubject/:messageId/edit","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TagPage","type":"COMMUNITY","urlPath":"/tag/:tagName","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"BlogBoardPage","type":"BLOG","urlPath":"/category/:categoryId/blog/:boardId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"OccasionMessagePage","type":"OCCASION_TOPIC","urlPath":"/event/:boardId/:messageSubject/:messageId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ManageContentPage","type":"COMMUNITY","urlPath":"/managecontent","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ClosedMembershipNodeNonMembersPage","type":"GROUP_HUB","urlPath":"/closedgroup/:groupHubId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CommunityPage","type":"COMMUNITY","urlPath":"/","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForumMessagePage","type":"FORUM_TOPIC","urlPath":"/discussions/:boardId/:messageSubject/:messageId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"IdeaPostPage","type":"IDEA","urlPath":"/category/:categoryId/ideas/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1730142000000,"localOverride":null,"page":{"id":"CommunityHub.Page","type":"CUSTOM","urlPath":"/Directory","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"BlogMessagePage","type":"BLOG_ARTICLE","urlPath":"/blog/:boardId/:messageSubject/:messageId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"RegistrationPage","type":"USER","urlPath":"/register","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"EditGroupHubPage","type":"GROUP_HUB","urlPath":"/group/:groupHubId/edit","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForumEditPage","type":"FORUM","urlPath":"/discussions/:boardId/:messageSubject/:messageId/edit","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ResetPasswordPage","type":"USER","urlPath":"/resetpassword/:userId/:resetPasswordToken","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1730142000000,"localOverride":null,"page":{"id":"AllBlogs.Page","type":"CUSTOM","urlPath":"/blogs","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TkbMessagePage","type":"TKB_ARTICLE","urlPath":"/kb/:boardId/:messageSubject/:messageId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"BlogEditPage","type":"BLOG","urlPath":"/blog/:boardId/:messageSubject/:messageId/edit","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ManageUsersPage","type":"USER","urlPath":"/users/manage/:tab?/:manageUsersTab?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForumReplyPage","type":"FORUM_REPLY","urlPath":"/discussions/:boardId/:messageSubject/:messageId/replies/:replyId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"PrivacyPolicyPage","type":"COMMUNITY","urlPath":"/privacypolicy","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"NotificationPage","type":"COMMUNITY","urlPath":"/notifications","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"UserPage","type":"USER","urlPath":"/users/:login/:userId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"OccasionReplyPage","type":"OCCASION_REPLY","urlPath":"/event/:boardId/:messageSubject/:messageId/comments/:replyId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ManageMembersPage","type":"GROUP_HUB","urlPath":"/group/:groupHubId/manage/:tab?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"SearchResultsPage","type":"COMMUNITY","urlPath":"/search","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"BlogReplyPage","type":"BLOG_REPLY","urlPath":"/blog/:boardId/:messageSubject/:messageId/replies/:replyId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"GroupHubPage","type":"GROUP_HUB","urlPath":"/group/:groupHubId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TermsOfServicePage","type":"COMMUNITY","urlPath":"/termsofservice","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"CategoryPage","type":"CATEGORY","urlPath":"/category/:categoryId","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"ForumViewAllTopicsPage","type":"FORUM","urlPath":"/category/:categoryId/discussions/:boardId/all-topics/(/:after|/:before)?","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"TkbPostPage","type":"TKB","urlPath":"/category/:categoryId/kbs/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"},{"lastUpdatedTime":1744410786543,"localOverride":null,"page":{"id":"GroupHubPostPage","type":"GROUP_HUB","urlPath":"/group/:groupHubId/:boardId/create","__typename":"PageDescriptor"},"__typename":"PageResource"}],"localOverride":false},"CachedAsset:text:en_US-components/context/AppContext/AppContextProvider-0":{"__typename":"CachedAsset","id":"text:en_US-components/context/AppContext/AppContextProvider-0","value":{"noCommunity":"Cannot find community","noUser":"Cannot find current user","noNode":"Cannot find node with id {nodeId}","noMessage":"Cannot find message with id {messageId}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/common/Loading/LoadingDot-0":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/common/Loading/LoadingDot-0","value":{"title":"Loading..."},"localOverride":false},"User:user:-1":{"__typename":"User","id":"user:-1","uid":-1,"login":"Deleted","email":"","avatar":null,"rank":null,"kudosWeight":1,"registrationData":{"__typename":"RegistrationData","status":"ANONYMOUS","registrationTime":null,"confirmEmailStatus":false,"registrationAccessLevel":"VIEW","ssoRegistrationFields":[]},"ssoId":null,"profileSettings":{"__typename":"ProfileSettings","dateDisplayStyle":{"__typename":"InheritableStringSettingWithPossibleValues","key":"layout.friendly_dates_enabled","value":"false","localValue":"true","possibleValues":["true","false"]},"dateDisplayFormat":{"__typename":"InheritableStringSetting","key":"layout.format_pattern_date","value":"MMM dd yyyy","localValue":"MM-dd-yyyy"},"language":{"__typename":"InheritableStringSettingWithPossibleValues","key":"profile.language","value":"en-US","localValue":"en","possibleValues":["en-US"]}},"deleted":false},"Theme:customTheme1":{"__typename":"Theme","id":"customTheme1"},"Category:category:microsoft-sentinel":{"__typename":"Category","id":"category:microsoft-sentinel","entityType":"CATEGORY","displayId":"microsoft-sentinel","nodeType":"category","depth":4,"title":"Microsoft Sentinel","shortTitle":"Microsoft Sentinel","parent":{"__ref":"Category:category:microsoft-security"}},"Category:category:top":{"__typename":"Category","id":"category:top","displayId":"top","nodeType":"category","depth":0,"title":"Top","entityType":"CATEGORY","shortTitle":"Top"},"Category:category:communities":{"__typename":"Category","id":"category:communities","displayId":"communities","nodeType":"category","depth":1,"parent":{"__ref":"Category:category:top"},"title":"Communities","entityType":"CATEGORY","shortTitle":"Communities"},"Category:category:products-services":{"__typename":"Category","id":"category:products-services","displayId":"products-services","nodeType":"category","depth":2,"parent":{"__ref":"Category:category:communities"},"title":"Products","entityType":"CATEGORY","shortTitle":"Products"},"Category:category:microsoft-security":{"__typename":"Category","id":"category:microsoft-security","displayId":"microsoft-security","nodeType":"category","depth":3,"parent":{"__ref":"Category:category:products-services"},"title":"Microsoft Security","entityType":"CATEGORY","shortTitle":"Microsoft Security","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Blog:board:MicrosoftSentinelBlog":{"__typename":"Blog","id":"board:MicrosoftSentinelBlog","entityType":"BLOG","displayId":"MicrosoftSentinelBlog","nodeType":"board","depth":5,"conversationStyle":"BLOG","title":"Microsoft Sentinel Blog","description":"

Microsoft Sentinel is a cloud-native SIEM, enriched with AI and automation to provide expansive visibility across your digital environment.

\n\n\n

When evaluating various solutions, your peers value hearing from people like you who’ve used the product. Review Microsoft Sentinel by filling out a Gartner Peer Insights survey and receive a $25 USD gift card (for customers only). Here are the Privacy/Guideline links: Microsoft Privacy Statement, Gartner’s Community Guidelines & Gartner Peer Insights Review Guide.

","avatar":null,"profileSettings":{"__typename":"ProfileSettings","language":null},"parent":{"__ref":"Category:category:microsoft-sentinel"},"ancestors":{"__typename":"CoreNodeConnection","edges":[{"__typename":"CoreNodeEdge","node":{"__ref":"Community:community:gxcuf89792"}},{"__typename":"CoreNodeEdge","node":{"__ref":"Category:category:communities"}},{"__typename":"CoreNodeEdge","node":{"__ref":"Category:category:products-services"}},{"__typename":"CoreNodeEdge","node":{"__ref":"Category:category:microsoft-security"}},{"__typename":"CoreNodeEdge","node":{"__ref":"Category:category:microsoft-sentinel"}}]},"userContext":{"__typename":"NodeUserContext","canAddAttachments":false,"canUpdateNode":false,"canPostMessages":false,"isSubscribed":false},"boardPolicies":{"__typename":"BoardPolicies","canPublishArticleOnCreate":{"__typename":"PolicyResult","failureReason":{"__typename":"FailureReason","message":"error.lithium.policies.forums.policy_can_publish_on_create_workflow_action.accessDenied","key":"error.lithium.policies.forums.policy_can_publish_on_create_workflow_action.accessDenied","args":[]}}},"shortTitle":"Microsoft Sentinel Blog","repliesProperties":{"__typename":"RepliesProperties","sortOrder":"REVERSE_PUBLISH_TIME","repliesFormat":"threaded"},"eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/","tagProperties":{"__typename":"TagNodeProperties","tagsEnabled":{"__typename":"PolicyResult","failureReason":null}},"requireTags":false,"tagType":"PRESET_ONLY"},"AssociatedImage:{\"url\":\"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/cmstNC05WEo0blc\"}":{"__typename":"AssociatedImage","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/cmstNC05WEo0blc","height":512,"width":512,"mimeType":"image/png"},"Rank:rank:4":{"__typename":"Rank","id":"rank:4","position":6,"name":"Microsoft","color":"333333","icon":{"__ref":"AssociatedImage:{\"url\":\"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/cmstNC05WEo0blc\"}"},"rankStyle":"OUTLINE"},"User:user:293879":{"__typename":"User","id":"user:293879","uid":293879,"login":"Ofer_Shezaf","deleted":false,"avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0yOTM4NzktMkFERzNl?image-coordinates=0%2C9%2C990%2C998"},"rank":{"__ref":"Rank:rank:4"},"email":"","messagesCount":272,"biography":null,"topicsCount":36,"kudosReceivedCount":383,"kudosGivenCount":4,"kudosWeight":1,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2019-03-01T11:51:50.376-08:00","confirmEmailStatus":null},"followersCount":null,"solutionsCount":12},"BlogTopicMessage:message:803891":{"__typename":"BlogTopicMessage","uid":803891,"subject":"Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","id":"message:803891","revisionNum":173,"repliesCount":78,"author":{"__ref":"User:user:293879"},"depth":0,"hasGivenKudo":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"conversation":{"__ref":"Conversation:conversation:803891"},"messagePolicies":{"__typename":"MessagePolicies","canPublishArticleOnEdit":{"__typename":"PolicyResult","failureReason":{"__typename":"FailureReason","message":"error.lithium.policies.forums.policy_can_publish_on_edit_workflow_action.accessDenied","key":"error.lithium.policies.forums.policy_can_publish_on_edit_workflow_action.accessDenied","args":[]}},"canModerateSpamMessage":{"__typename":"PolicyResult","failureReason":{"__typename":"FailureReason","message":"error.lithium.policies.feature.moderation_spam.action.moderate_entity.allowed.accessDenied","key":"error.lithium.policies.feature.moderation_spam.action.moderate_entity.allowed.accessDenied","args":[]}}},"contentWorkflow":{"__typename":"ContentWorkflow","state":"PUBLISH","scheduledPublishTime":null,"scheduledTimezone":null,"userContext":{"__typename":"MessageWorkflowContext","canSubmitForReview":null,"canEdit":false,"canRecall":null,"canSubmitForPublication":null,"canReturnToAuthor":null,"canPublish":null,"canReturnToReview":null,"canSchedule":false},"shortScheduledTimezone":null},"readOnly":false,"editFrozen":false,"moderationData":{"__ref":"ModerationData:moderation_data:803891"},"teaser":"

Want to connect a source system to Sentinel to send events? Even if not on the official source list, this is probably supported, and if not a custom community solution is avaliable. Here you can find information about it.

","body":"

(Last updated Apr 20th, 2021)

\n

 

\n

Please note that as the built-in list of connectors in Azure Sentinel is growing, this list is not actively maintained anymore. Refer to the Azure Sentinel connector documentation for more information. 

\n

 

\n

Source types

\n

 

\n

Built-in

\n

Built-in connectors are included in the Azure Sentinel documentation and the data connectors pane in the product itself. Those connectors are based on one of the technologies listed below. Therefore a built-in connector will have a type: CEF, Syslog, Direct, and so forth.

\n

 

\n

Syslog and CEF

\n

Most network and security systems support either Syslog or CEF (which stands for Common Event Format) over Syslog as means for sending data to a SIEM. This makes Syslog or CEF the most straightforward ways to stream security and networking events to Azure Sentinel.

\n

 

\n\n

 

\n

The advantage of CEF over Syslog is that it ensures the data is normalized, making it more immediately useful for analysis using Sentinel. However, unlike many other SIEM products, Sentinel allows ingesting unparsed Syslog events and performing analytics on them using query time parsing. 

\n

 

\n

The number of systems supporting Syslog or CEF is in the hundreds, making the table below by no means comprehensive. We will update this list continuously. The table provides links to the source device's vendor documentation for configuring the device to send events in Syslog or CEF.

\n

 

\n
Tip: Want to ingest test CEF data? here is how to do that.
\n

 

\n

Direct

\n

Most Microsoft cloud sources and many other clouds and on-prem systems can send to Azure Sentinel natively. For Microsoft Azure sources, this often uses their diagnostics feature, on which you can read more here.

\n

 

\n

Agent

\n

The Log Analytics agent can collect different types of events from servers and endpoints listed here. To learn more about the agent, read Azure Sentinel Agent: Collecting telemetry from on-prem and IaaS server.

\n

 

\n

Threat Intelligence (TI)

\n

You can use one of the threat intelligence connectors:

\n\n

to ingest threat intelligence indicators, which are used by Azure Sentinel's built-in TI analytics rules, and to build your own rules. You can read more about the Threat Intelligence connectors in module #6 of the Azure Sentinel Ninja Training 

\n

 

\n

Custom: Logic Apps, Logstash, Azure Functions, and others

\n

In addition to CEF and Syslog, many solutions are based on Sentinel's data collector API and create custom log tables in the workspace. Those belong to 3 groups:

\n\n

You can read more about custom connectors here.

\n

 

\n

Automation and integration

\n

While all the types above focused on getting telemetry into Azure Sentinel, connectors marked as automation/integration enable Azure Sentinel to implement other use cases such as sending information to another system or performing an action on another system. Those might be API-based on integration or Logic App-based integrations. 

\n

 

\n

The Grand List

\n

 

\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n
\n

Vendor

\n
\n

Product

\n
\n

Connector
Type

\n
\n

Connecting and using

\n
AgariPhishing Defense and Brand ProtectionBuilt-in (Function, Graph Security API)Instructions
AI VectraDetectBuilt-in (CEF)Instructions
Akamai Built-in (CEF)Instructions
\n

Alcide

\n
\n

kAudit

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

AlgoSec

\n
\n

ASMS

\n
\n

CEF

\n
\n

Instructions and examples

\n
\n

Anomali

\n
\n

Limo

\n
\n

Built-in (TAXII)

\n
\n

Instructions

\n
\n

Anomali

\n
\n

ThreatStream

\n
Built-in (TI Platform)\n

Instructions

\n
\n

Anomali

\n
\n

Match

\n
Integration\n

Overview and instructions

\n
\n

Apache

\n
\n

httpd

\n
\n

Built-in (Agent custom logs)

\n
\n

Instructions

\n

Also, read using rsyslog or logger as a file forwarder for an alternative method.

\n
\n

Apache

\n
\n

Kafka

\n
\n

Logstash

\n
\n

See Logstash plug-in. Use to get events sent using Kafka, not for Kafka's own audit events.

\n
\n

Aruba

\n
\n

ClearPass

\n
\n

CEF

\n
\n

Instructions

\n
AT&T Cyber\n

AlienVault OTX

\n
\n

TI (Platform)

\n
\n

Using Logic Apps, See instructions

\n
\n

AWS

\n
\n

CloudTrail

\n
\n

Built-in

\n
\n

Sentinel built-in connector

\n
\n

AWS

\n
\n

CloudTrail S3 logs

\n
\n

Custom

\n
\n

Using an Azure Function. See here.

\n

Using an AWS Lambda Function. See here.

\n
\n

AWS

\n
\n

CloudWatch

\n
\n

Logstash

\n
\n

See Logstash Plug-in.

\n
\n

AWS

\n
\n

Kinesis

\n
\n

Logstash

\n
\n

See Logstash Plug-in.

\n
\n

AWS

\n
\n

Object Level S3 Logging

\n
\n

Logstash 

\n
\n

See here.

\n
\n

AWS

\n
\n

Security Hub

\n
\n

Custom

\n
\n

Azure Function. See here.

\n
\n

Barracuda

\n
\n

WAF

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Barracuda

\n
\n

CloudGen Firewall

\n
\n

API

\n
\n

Sentinel built-in connector

\n
\n

BETTER Mobile

\n
\n

Threat Defense

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Beyond Security

\n
\n

beSECURE

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Carbon Black

\n
\n

Cloud Endpoint Standard (Cb Defense)

\n
\n

Built-in (Function)

\n

Syslog

\n
\n

Sentinel built-in connector 

\n

 

\n

Instructions

\n
\n

Carbon Black

\n
\n

(Cb Response)

\n
\n

Syslog

\n
\n

Instructions

\n
Checkpoint CEF\n

Sentinel Built-in connector

\n
CiscoACSSyslog\n

Instructions

\n
CiscoASACisco (CEF)\n

Sentinel built-in connector

\n

Notes:

\n

- Cisco ASA support uses Sentinel's CEF pipeline. However, Cisco's logging is not in CEF format.

\n

- Make sure you disable logging timestamp using \"no logging timestamp\". See here for more details.

\n
CiscoCloud Security Gateway (CWS)CEFUse the Cisco Advanced Web Security Reporting.
CiscoFTDCisco (CEF)FTP Platform logs are compatible with ASA logs and can use the same connector (see here).
CiscoIOSSyslogInstructions
CiscoISE  (NAC)SyslogInstructions
CiscoWeb Security Appliance (WSA)CEFUse the Cisco Advanced Web Security Reporting.
\n

Cisco

\n
\n

Meraki

\n
\n

Syslog

\n
\n

Instructions

\n

Event Types and Log Samples

\n
CiscoeStreamerCEF\n

Using enCore

\n
CiscoFirepower Threat Defense\n

CEF

\n

Syslog

\n
\n

Using eStreamer enCore

\n

Instructions, Event reference

\n
CiscoFireSight\n

CEF

\n
\n

Using eStreamer enCore

\n
CiscoIronPort Web Security ApplianceSyslog\n

Instructions

\n
CiscoNexusSyslog\n

Instructions

\n
CiscoUmbrellaBuilt-in (Function)\n

Instructions

\n

Also, see this blog post

\n

for a custom solution

\n
CiscoUnified Computing System (UCS)Built-in (Syslog)\n

Instructions

\n
CiscoViptela SD-WANSyslog\n

Instructions

\n
CitrixAnalyticsBuilt-in (Direct)\n

Instructions

\n
CitrixNetScaler Syslog\n

Instructions

\n

Message format

\n
CitrixNetScaler App FWBuilt-in (CEF)Instructions
\n

Clearswift

\n
\n

Web Security Gateway

\n
Syslog\n

Instructions

\n
\n

Cloudflare

\n
\n

 

\n
 \n

Use Cloudflare Logpush to send to storage and a custom connector to read events from storage (for example, reading AWS S3 buckets).

\n
\n

Cribl

\n
\n

LogStream

\n
\n

Direct

\n
\n

Instructions

\n
\n

CrowdStrike

\n
\n

Falcon

\n
\n

CEF

\n
\n

Instructions. Use a SIEM connector installed on-premises.

\n
\n

CyberArk

\n
Endpoint Privilege Manager (EPM)\n

Syslog

\n

Logstash

\n
\n

Instructions (for both)

\n
\n

CyberArk

\n
Privileged Access Security (PTA)\n

CEF

\n
\n

Instructions

\n

Message format

\n
\n

Darktrace

\n
\n

Immune

\n
\n

CEF

\n
\n

See announcement. Contact vendor for instructions.

\n
\n

Digital Guardian

\n
\n

 

\n
\n

CEF

\n
\n

3rd party instructions

\n
\n

DocuSign

\n
\n

Monitor

\n
\n

Custom

\n
\n

See this blog post

\n
\n

Duo Security

\n
\n

 

\n
\n

CEF

\n
\n

Using Duo LogSync

\n
\n

Extrahop

\n
\n

Reveal

\n
\n

Built-in (CEF)

\n
\n

Instructions

\n
\n

F5

\n
\n

ASM (WAF)

\n
\n

Built-in (CEF)

\n
\n

Instructions

\n
\n

F5

\n
\n

BigIP (System, LTM, AFM, ASM, APM, AVR)

\n
\n

Built-in (Direct)

\n
\n

Instructions 

\n
\n

Fastly

\n
WAFCustom\n

See this blog post (Logic Apps or Azure Function)

\n
\n

Forcepoint

\n
Web Security (WebSense)CEF\n

Instructions

\n

Detailed reference

\n
\n

Forcepoint

\n
CASBCEF\n

Sentinel built-in connector

\n
\n

Forcepoint

\n
DLPDirect\n

Sentinel built-in connector

\n
\n

Forcepoint

\n
NGFWCEF\n

Sentinel built-in connector

\n
\n

Forescout

\n
CounterActCEF\n

Instructions

\n
\n

Fortinet

\n
 CEF\n

Sentinel built-in connector

\n

Log message reference

\n

CEF mapping and examples

\n
\n

Fortinet

\n
\n

FortiSIEM

\n
\n

CEF

\n
\n

Instructions

\n
\n

Fortinet

\n
\n

FortiSOAR

\n
\n

Integration

\n
\n

Instructions

\n
\n

GitHub

\n
\n

 

\n
\n

Custom

\n
\n

See connector, rules, and hunting queries 

\n

here

\n
\n

GCP

\n
\n

Cloud Storage

\n
\n

Logstash

\n
\n

See Plug-in. Use to get events stored in GCP Cloud Storage, not for Cloud Storage own audit events.

\n
\n

GCP

\n
\n

Pub/Sub

\n
\n

Logstash

\n
\n

See Plug-in. Use to get events sent using Pub/Sub, not for Pub/Sub own audit events.

\n
\n

GCP

\n
\n

Stacdriver

\n
\n

Logstash

\n

 

\n

Custom

\n
\n

Through GCP Cloud Storage or GCP Pub/Sub as described above. 

\n

Using GCP Cloud Function. See here.

\n
\n

Group-IB

\n
\n

 

\n
\n

Custom (TI Platform)

\n
\n

Using Logic Apps. See instructions

\n
\n

GuardiCore

\n
\n

Centra

\n
\n

CEF

\n
\n

Contact vendor for instructions

\n
\n

HP

\n
\n

Printers

\n
\n

Syslog

\n
\n

Instructions

\n
\n

IBM

\n
\n

iSeries

\n
\n

CEF

\n
\n

See here.

\n
\n

IBM

\n
\n

QRadar events

\n
\n

Syslog

\n
\n

Forward raw events or correlation events in raw, parsed, or JSON format. See instructions.

\n
\n

IBM

\n
\n

QRadar offenses

\n
\n

Custom (Function)

\n
\n

Blog post

\n
\n

IBM

\n
\n

X-Force

\n
\n

TI (TAXII)

\n
\n

Instructions

\n
\n

IBM

\n
\n

zSecure

\n
\n

CEF

\n
\n

See What's new for zSecure V2.3.0

\n

Note that it supports alerts only.

\n
\n

Illusive 

\n
\n

Attack Management System

\n
\n

Syslog

\n
\n

Sentinel built-in connector

\n
\n

Imperva

\n
\n

SecureSphere

\n
\n

CEF

\n
\n

Instructions

\n
InfobloxNIOS\n

Built-in (Syslog)

\n
\n

Instructions

\n
InSights \n

TI (TAXII)

\n
\n

TAXII Instructions and related workbook

\n
JamfPro\n

Syslog

\n
\n

Instructions

\n
JuniperATP\n

CEF

\n
\n

Instructions

\n
JuniperJunOS based devices\n

Built-in (Syslog)

\n
\n

Instructions

\n
KasperskySecurity Center CEFInstructions
\n

ManageEngine

\n
\n

AD Audit Plus

\n
\n

CEF

\n
\n

Instructions (use ArcSight instructions)

\n
\n

ManageEngine

\n
\n

Exchange Reporter Plus

\n
\n

Syslog

\n
\n

Instructions

\n
\n

McAfee

\n
\n

ePO

\n
\n

Syslog

\n
\n

Instructions (Note: TLS only (requires rsyslog TLS configuration)

\n
\n

McAfee

\n
\n

MVISION EDR

\n
\n

Syslog

\n
\n

Instructions

\n
\n

McAfee

\n
\n

Web Gateway

\n
\n

CEF

\n
\n

Instructions

\n
\n

Microfocus

\n
\n

Fortify AppDefender

\n
\n

CEF

\n
Instructions (require authentication; contact vendor for further details).
\n

Microsoft

\n
\n

Active Directory

\n
\n

Agent

\n
\n

Most AD events are logged as part of security events. 

\n

Also, See in this list:

\n
    \n
  • LDAP auditing
  • \n
  • SMBv1 auditing
  • \n
\n
\n

Microsoft

\n
\n

Advanced Threat Protection (ATA)

\n
\n

CEF

\n
\n\n
\n

Microsoft

\n
\n

Azure Active Directory (AAD)

\n
\n

Built-in (Diagnostics)

\n
\n\n
\n

Microsoft

\n
\n

Azure Active Directory Domain Services

\n
\n

Diagnostics

\n
\n\n
\n

Microsoft

\n
\n

Azure Active Directory Identity Protection

\n
\n

 

\n
\n\n
\n

Microsoft

\n
\n

Azure

\n

Azure Activity

\n

Azure Subscriptions

\n

Azure Management Groups

\n
\n

Direct

\n
\n\n
\n

Microsoft

\n
\n

Application Insights

\n
\n

Direct

\n
\n\n
\n

Microsoft

\n
App Services & Web Application monitoring \n

Direct

\n
Instructions and reference architecture 
\n

Microsoft

\n
\n

Azure B2B

\n
\n

Direct

\n
Included as part of AAD events
\n

Microsoft

\n
\n

Azure B2C

\n
\n

Direct

\n
collect B2C logs from your B2C tenant to your primary tenant AAD logs as described here
\n

Microsoft

\n
\n

Azure Cosmos DB

\n
\n

Direct

\n
Instructions
\n

Microsoft

\n
\n

Azure Data Lake Gen 1

\n
\n

Direct

\n
\n\n
\n

Microsoft

\n
\n

Azure Data Factory

\n
\n

Direct

\n
Instructions
\n

Microsoft

\n
\n

Azure Databricks

\n
\n

Direct

\n
Instructions
\n

Microsoft

\n
\n

Azure DDOS

\n
\n

Built-in (diagnostics)

\n
\n\n
MicrosoftAzure Defender  and Azure Security Center (ASC)\n

Direct

\n
\n\n
\n

Microsoft

\n
\n

Azure Defender for IoT

\n
\n

Built-in (Direct)

\n
\n\n
\n

Microsoft

\n
\n

Azure DevOps

\n
\n

Direct

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Azure Event Hub (subscription)

\n
\n

Logstash

\n
\n

See Logstash Plug-in. Use to get events sent using an Event Hub, not for Event Hub own audit events.

\n
\n

Microsoft

\n
\n

Azure Files

\n
\n

Direct (Diagnostics)

\n
\n

Instructions

\n

Schema information

\n
\n

Microsoft

\n
\n

Azure Firewall

\n
\n

Built-in (diagnostics)

\n
\n\n
\n

Microsoft

\n
\n

Azure Front Door

\n
\n

Direct

\n
Instructions
MicrosoftAzure Key Vault (AKV)\n

Built-in (Diagnostics)

\n
\n

Connect:

\n\n

Use:

\n\n
MicrosoftAzure Information Protection (Classic and Unified Labeling)\n

Built-in (Direct)

\n
Instructions
MicrosoftAzure Kubernetes Service (AKS)\n

Direct

\n
\n\n
MicrosoftAzure Log Analytics\n

Direct

\n
Collect query auditing and other metrics: Instructions
MicrosoftAzure Logic Apps\n

Direct

\n
Instructions
MicrosoftAzure Network Security Groups (NSG)\n

Direct

\n
\n\n
MicrosoftAzure SQL\n

Built-in (diagnostics)

\n
\n\n
MicrosoftAzure SQL Managed Instance\n

Direct

\n
Instructions
MicrosoftAzure Site Recovery\n

Direct

\n
Instructions
MicrosoftAzure Storage\n

Direct

\n
\n

Instructions

\n

Blog: Blob and File Storage Investigations

\n
MicrosoftAzure Storage Content\n

Custom (Azure Function)

\n
Ingest the content of Azure Storage Blobs. See GitHub.
MicrosoftAzure Synapse\n

Direct

\n
Instructions
MicrosoftAzure Web Application Firewall (WAF)\n

Built-in (Diagnostics)

\n
\n\n
\n

Microsoft

\n
\n

BitLocker / MBAM

\n
\n

Agent

\n
\n

Using Windows Event collection. Blog post

\n
\n

Microsoft

\n
\n

Cloud App Security (Alerts, Discovery logs)

\n
\n

Built-in (Direct)

\n
\n\n
\n

Microsoft

\n
\n

Cloud App Security (Activity Log)

\n
\n

CEF

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Defender for Office

\n
\n

Built-in

\n

Custom

\n

 

\n

 

\n

 

\n
\n

For AIRs alerts: instructions

\n

For other alerts: Use Either a Logic App or an Azure function custom connector. For the Azure Function connector, query for RecordType_d == \"28\", \"41\" or \"47\" .

\n
\n

Microsoft

\n
\n

Defender for Identity (Azure ATP) Alerts

\n
\n

Built-in

\n
\n\n
\n

Microsoft

\n
\n

Defender for Identity (Azure ATP) Events

\n
\n

CEF

\n
\n\n
\n

Microsoft

\n
\n

Desktop Analytics

\n
\n

Direct

\n
\n

Connect

\n
\n

Microsoft

\n
\n

DNS

\n
\n

Agent

\n
\n

Sentinel built-in connector

\n
\n

Microsoft

\n
\n

Dynamics 365

\n
\n

Built-in

\n
\n

Sentinel built-in connector

\n
\n

Microsoft

\n
\n

Dynamics (not 365)

\n
\n

Agent

\n
\n

Using IIS logs

\n

Using Dynamics Trace Files

\n
\n

Microsoft

\n
\n

IIS

\n
\n

Agent

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Intune

\n
\n

Direct

\n
\n

Connect

\n

Use cases

\n
\n

Microsoft

\n
\n

LDAP (Windows Server)

\n
\n

Agent

\n
\n

Configure AD diagnostics logging and set \"16 LDAP Interface Events\" to 2 or above.

\n
\n

Microsoft

\n
\n

Office 365 (Exchange, SharePoint, OneDrive, DLP Alerts)

\n
\n

Built-in

\n
\n

 

\n

Sentinel built-in connector

\n

For details about DLP alerts, read here

\n
\n

Microsoft 

\n
\n

Office 365 (Microsoft Defender for Office; formerly Office ATP, PowerBI, Yammer, Sway, Forms, eDiscovery, and others)

\n
\n

Custom (Azure Function, Logic Apps)

\n
\n

Use Either a Logic App or an Azure function custom connector

\n
\n

Microsoft

\n
\n

Office 365 e-mail trace logs

\n
\n

Custom (Logic Apps)

\n
\n

See Blog Post.

\n
\n

Microsoft

\n
\n

PowerBI Embedded

\n
\n

Direct (Diagnostics)

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

SMBv1 (Windows Server)

\n
\n

Agent

\n
\n

See Enable Auditing on SMB Servers, and the CmdLet reference 

\n
\n

Microsoft

\n
\n

Teams (Call Logs)

\n
\n

Custom

\n
\n

Using Logic Apps

\n
\n

Microsoft

\n
\n

Teams (Management Activity)

\n
\n

Built-in

\n
\n\n
\n

Microsoft

\n
\n

Teams Shifts

\n
\n

Custom

\n
\n

Use Either a Logic App or an Azure function custom connector. For the Azure Function connector, query for RecordType_d == \"73\"

\n
\n

Microsoft

\n
\n

SCCM

\n
\n

Agent

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

SQL Server

\n
\n

Agent

\n
\n

Instructions, parser, rules, and hunting queries

\n

You can also audit at the engine level.

\n
\n

Microsoft

\n
\n

Sysmon

\n
\n

Agent

\n
\n

Using Windows Event collection. Blog post

\n
\n

Microsoft

\n
\n

Windows (Security Events)

\n
\n

Agent

\n
\n\n
\n

Microsoft

\n
\n

Windows (Other Events, Sysmon)

\n
\n

Agent

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Windows network connections

\n
\n

Agent

\n
\n

VM Insights

\n

Wire Data

\n
\n

Microsoft

\n
\n

Windows Firewall

\n
\n

Agent

\n
Sentinel built-in connector
\n

Microsoft

\n
\n

Windows Virtual Desktop

\n
\n

Direct

\n
\n\n
\n

Mimecast

\n
\n

 

\n
\n

Agent

\n
\n

Announcement. For technical instructions, contact the vendor.

\n
\n

Minerva Labs

\n
\n

 

\n
\n

CEF

\n
\n

Please ask the vendor for instructions.

\n
\n

MISP

\n
\n

 

\n
\n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
\n

NetApp

\n
\n

ONTAP

\n
\n

Syslog

\n
\n

Instructions

\n

Note that those are management activity audit logs and not file usage activity logs.

\n
\n

Netflow

\n
\n

 

\n
\n

Logstash

\n
\n

Use the Netflow codec plug-in

\n
\n

Nexthink

\n
\n

 

\n
\n

CEF

\n
\n

Instructions

\n
\n

Nozomi

\n
\n

Guardian

\n
\n

CEF

\n
\n

Contact vendor for details

\n
\n

NXlog

\n
\n

 

\n
\n

Direct

\n
\n

Instructions

\n
\n

Okta

\n
\n

SSO

\n
\n

Built-in (Function)

\n
\n

Instructions

\n
\n

One Identity

\n
\n

Safeguard

\n
\n

Built-in (CEF)

\n
\n

Instructions

\n
\n

Oracle

\n
\n

Cloud (OCI)

\n
\n

Custom (Azure Function)

\n
Available Here
\n

Oracle

\n
\n

DB

\n
\n

Syslog

\n
\n

Instructions

\n
\n

Orca

\n
\n

 

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

OSSEC

\n
\n

 

\n
\n

CEF

\n
\n

Instructions

\n
\n

Pager Duty

\n
\n

 

\n
\n

Automation (Playbook)

\n
\n

Blog post

\n
\n

Palo Alto

\n
\n

Cloudgenix

\n
\n

Syslog

\n
\n

Instructions

\n
\n

Palo Alto

\n
\n

Minemeld

\n
\n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
\n

Palo Alto

\n
\n

PanOS

\n
\n

CEF

\n
\n

Sentinel built-in connector

\n
\n

Palo Alto

\n
\n

Panorama

\n
\n

CEF

\n
\n

Instructions

\n
\n

Palo Alto

\n
\n

Prisma

\n
\n

Syslog

\n

Custom

\n
\n

Instructions, Fields

\n

Logic Apps using a Webhook and clarification

\n
\n

Palo Alto

\n
\n

Traps through Cortex

\n
\n

Syslog

\n
\n

Instructions

\n

Notes:

\n

- Require rsyslog configuration to support RFC5424

\n

- TLS only (requires rsyslog TLS configuration)

\n

- The certificate has to be signed by a public CA

\n
\n

Palo Alto

\n
\n

XDR

\n
\n

CEF

\n
\n

Instructions

\n
\n

Palo Alto

\n
\n

XSOAR

\n
\n

Integration

\n
\n

Forward Azure Sentinel incidents to Palo Alto XSOAR 

\n
\n

Perimeter 81

\n
\n

 

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Ping Identity

\n
\n

Federate

\n
\n

CEF

\n
\n

Instructions

\n
\n

Ping Identity

\n
\n

Provisioner

\n
\n

CEF

\n
\n

Instructions

\n
PostgressDBSyslog, Windows Event log\n

Instructions

\n
ProofpointOn DemandBuilt-in (API)\n

Instructions

\n
ProofpointTAPBuilt-in (Function)\n

Instructions

\n
PulseConnectBuilt-in (Syslog)\n

Instructions

\n
QualysVMBuilt-in (Function)\n

Instructions

\n
RadwareCloud WAFLogstash\n

Instructions

\n
RedHatOpenShiftSyslog
API
\n

Instructions for Syslog
Fluentd Log Analytics plugin for API

\n
RedHatAzure OpenShiftSyslog
Custom
\n

Instructions for Syslog
Fluentd Log Analytics plugin for API

\n
RiskIQ Action (Logic Apps)\n

Azure Logic-Apps built-in connector

\n
SalesforceService CloudBuilt-in (Function)\n

Instructions

\n
SAPHanaSyslog\n

Instructions (requires an SAP account)

\n
SentinelOne CEF\n

Please consult the vendor for instructions

\n
SNMP Syslog\n

Instructions

\n
Snort Agent\n

Instructions

\n
SonicWall CEF\n

Instructions

\n

Make sure you:
- Select local use 4 as the facility.

\n

- Select ArcSight as the Syslog format.

\n
SophosCentralCEFInstructions. Note that the script provided by Sophos has to be scheduled using a cron job, which is not documented on the reference page.
SophosXF FirewallBuilt-in (Syslog)Instructions
Squadra  secRMMBuilt-in (API)Instructions
Squid Proxy \n

Built-in (Agent)

\n

Syslog

\n
\n

Instructions

\n

 

\n

Configure access logs with either the TCP or UDP modules. Sentinel's built-in queries use the default log format.

\n
\n

Symantec

\n
\n

DLP

\n
\n

Syslog

\n

CEF

\n
\n

Instructions. Note that only UDP is supported

\n

Instructions. Uses response automation.

\n
\n

Symantec

\n
\n

ICDX

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Symantec

\n
\n

Proxy SG (Bluecoat)

\n
\n

Built-in (Syslog)

\n
\n

Instructions

\n
Symantec  Endpoint Protection ManagerSyslogInstructions  
SymantecCloud Workload ProtectionAPIInstructions
SymantecVIPBuilt-in (Syslog)Instructions
TheHive \n

Integration

\n
\n

Send new incidents to TheHive

\n
ThinkstCanary\n

Syslog

\n
\n

Instructions

\n
ThreatConnect \n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
ThreatQuotient \n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
ThycoticSecret Server\n

CEF

\n
\n

Instructions

\n
TitanHQWebTitan Cloud\n

Syslog

\n
\n

Instructions

\n
Trend Micro \n

CEF

\n
\n

Using Control Manager

\n

Using LogForwarder

\n
Trend MicroApax Central (Cloud and On-prem)\n

CEF

\n
\n

Instructions

\n
Trend MicroDeep Security\n

CEF

\n
\n

Sentinel built-in connector

\n
TufinSecureTrack\n

Syslog

\n
\n

Instructions

\n
\n

Varonis

\n
\n

DatAlert

\n
\n

CEF

\n
\n

Instructions

\n
WatchGuard CEFInstructions
Zimperium  
Mobile Threat DefenseBuilt-in (API)Instructions 
zScalerInternet Access (ZIA)Built-in (CEF)Instructions
zScalerPrivate Access (ZPA)LogstashUse LSS. Since LSS sends raw TCP but not Syslog, you will have to use Logstash and not Azure Sentinel's native connector. 
Zoom CustomUsing Azure Function. See blog post.
\n

 

","body@stringLength":"149153","rawBody":"

(Last updated Apr 20th, 2021)

\n

 

\n

Please note that as the built-in list of connectors in Azure Sentinel is growing, this list is not actively maintained anymore. Refer to the Azure Sentinel connector documentation for more information. 

\n

 

\n

Source types

\n

 

\n

Built-in

\n

Built-in connectors are included in the Azure Sentinel documentation and the data connectors pane in the product itself. Those connectors are based on one of the technologies listed below. Therefore a built-in connector will have a type: CEF, Syslog, Direct, and so forth.

\n

 

\n

Syslog and CEF

\n

Most network and security systems support either Syslog or CEF (which stands for Common Event Format) over Syslog as means for sending data to a SIEM. This makes Syslog or CEF the most straightforward ways to stream security and networking events to Azure Sentinel.

\n

 

\n\n

 

\n

The advantage of CEF over Syslog is that it ensures the data is normalized, making it more immediately useful for analysis using Sentinel. However, unlike many other SIEM products, Sentinel allows ingesting unparsed Syslog events and performing analytics on them using query time parsing. 

\n

 

\n

The number of systems supporting Syslog or CEF is in the hundreds, making the table below by no means comprehensive. We will update this list continuously. The table provides links to the source device's vendor documentation for configuring the device to send events in Syslog or CEF.

\n

 

\n
Tip: Want to ingest test CEF data? here is how to do that.
\n

 

\n

Direct

\n

Most Microsoft cloud sources and many other clouds and on-prem systems can send to Azure Sentinel natively. For Microsoft Azure sources, this often uses their diagnostics feature, on which you can read more here.

\n

 

\n

Agent

\n

The Log Analytics agent can collect different types of events from servers and endpoints listed here. To learn more about the agent, read Azure Sentinel Agent: Collecting telemetry from on-prem and IaaS server.

\n

 

\n

Threat Intelligence (TI)

\n

You can use one of the threat intelligence connectors:

\n\n

to ingest threat intelligence indicators, which are used by Azure Sentinel's built-in TI analytics rules, and to build your own rules. You can read more about the Threat Intelligence connectors in module #6 of the Azure Sentinel Ninja Training 

\n

 

\n

Custom: Logic Apps, Logstash, Azure Functions, and others

\n

In addition to CEF and Syslog, many solutions are based on Sentinel's data collector API and create custom log tables in the workspace. Those belong to 3 groups:

\n\n

You can read more about custom connectors here.

\n

 

\n

Automation and integration

\n

While all the types above focused on getting telemetry into Azure Sentinel, connectors marked as automation/integration enable Azure Sentinel to implement other use cases such as sending information to another system or performing an action on another system. Those might be API-based on integration or Logic App-based integrations. 

\n

 

\n

The Grand List

\n

 

\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n
\n

Vendor

\n
\n

Product

\n
\n

Connector
Type

\n
\n

Connecting and using

\n
AgariPhishing Defense and Brand ProtectionBuilt-in (Function, Graph Security API)Instructions
AI VectraDetectBuilt-in (CEF)Instructions
Akamai Built-in (CEF)Instructions
\n

Alcide

\n
\n

kAudit

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

AlgoSec

\n
\n

ASMS

\n
\n

CEF

\n
\n

Instructions and examples

\n
\n

Anomali

\n
\n

Limo

\n
\n

Built-in (TAXII)

\n
\n

Instructions

\n
\n

Anomali

\n
\n

ThreatStream

\n
Built-in (TI Platform)\n

Instructions

\n
\n

Anomali

\n
\n

Match

\n
Integration\n

Overview and instructions

\n
\n

Apache

\n
\n

httpd

\n
\n

Built-in (Agent custom logs)

\n
\n

Instructions

\n

Also, read using rsyslog or logger as a file forwarder for an alternative method.

\n
\n

Apache

\n
\n

Kafka

\n
\n

Logstash

\n
\n

See Logstash plug-in. Use to get events sent using Kafka, not for Kafka's own audit events.

\n
\n

Aruba

\n
\n

ClearPass

\n
\n

CEF

\n
\n

Instructions

\n
AT&T Cyber\n

AlienVault OTX

\n
\n

TI (Platform)

\n
\n

Using Logic Apps, See instructions

\n
\n

AWS

\n
\n

CloudTrail

\n
\n

Built-in

\n
\n

Sentinel built-in connector

\n
\n

AWS

\n
\n

CloudTrail S3 logs

\n
\n

Custom

\n
\n

Using an Azure Function. See here.

\n

Using an AWS Lambda Function. See here.

\n
\n

AWS

\n
\n

CloudWatch

\n
\n

Logstash

\n
\n

See Logstash Plug-in.

\n
\n

AWS

\n
\n

Kinesis

\n
\n

Logstash

\n
\n

See Logstash Plug-in.

\n
\n

AWS

\n
\n

Object Level S3 Logging

\n
\n

Logstash 

\n
\n

See here.

\n
\n

AWS

\n
\n

Security Hub

\n
\n

Custom

\n
\n

Azure Function. See here.

\n
\n

Barracuda

\n
\n

WAF

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Barracuda

\n
\n

CloudGen Firewall

\n
\n

API

\n
\n

Sentinel built-in connector

\n
\n

BETTER Mobile

\n
\n

Threat Defense

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Beyond Security

\n
\n

beSECURE

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Carbon Black

\n
\n

Cloud Endpoint Standard (Cb Defense)

\n
\n

Built-in (Function)

\n

Syslog

\n
\n

Sentinel built-in connector 

\n

 

\n

Instructions

\n
\n

Carbon Black

\n
\n

(Cb Response)

\n
\n

Syslog

\n
\n

Instructions

\n
Checkpoint CEF\n

Sentinel Built-in connector

\n
CiscoACSSyslog\n

Instructions

\n
CiscoASACisco (CEF)\n

Sentinel built-in connector

\n

Notes:

\n

- Cisco ASA support uses Sentinel's CEF pipeline. However, Cisco's logging is not in CEF format.

\n

- Make sure you disable logging timestamp using \"no logging timestamp\". See here for more details.

\n
CiscoCloud Security Gateway (CWS)CEFUse the Cisco Advanced Web Security Reporting.
CiscoFTDCisco (CEF)FTP Platform logs are compatible with ASA logs and can use the same connector (see here).
CiscoIOSSyslogInstructions
CiscoISE  (NAC)SyslogInstructions
CiscoWeb Security Appliance (WSA)CEFUse the Cisco Advanced Web Security Reporting.
\n

Cisco

\n
\n

Meraki

\n
\n

Syslog

\n
\n

Instructions

\n

Event Types and Log Samples

\n
CiscoeStreamerCEF\n

Using enCore

\n
CiscoFirepower Threat Defense\n

CEF

\n

Syslog

\n
\n

Using eStreamer enCore

\n

Instructions, Event reference

\n
CiscoFireSight\n

CEF

\n
\n

Using eStreamer enCore

\n
CiscoIronPort Web Security ApplianceSyslog\n

Instructions

\n
CiscoNexusSyslog\n

Instructions

\n
CiscoUmbrellaBuilt-in (Function)\n

Instructions

\n

Also, see this blog post

\n

for a custom solution

\n
CiscoUnified Computing System (UCS)Built-in (Syslog)\n

Instructions

\n
CiscoViptela SD-WANSyslog\n

Instructions

\n
CitrixAnalyticsBuilt-in (Direct)\n

Instructions

\n
CitrixNetScaler Syslog\n

Instructions

\n

Message format

\n
CitrixNetScaler App FWBuilt-in (CEF)Instructions
\n

Clearswift

\n
\n

Web Security Gateway

\n
Syslog\n

Instructions

\n
\n

Cloudflare

\n
\n

 

\n
 \n

Use Cloudflare Logpush to send to storage and a custom connector to read events from storage (for example, reading AWS S3 buckets).

\n
\n

Cribl

\n
\n

LogStream

\n
\n

Direct

\n
\n

Instructions

\n
\n

CrowdStrike

\n
\n

Falcon

\n
\n

CEF

\n
\n

Instructions. Use a SIEM connector installed on-premises.

\n
\n

CyberArk

\n
Endpoint Privilege Manager (EPM)\n

Syslog

\n

Logstash

\n
\n

Instructions (for both)

\n
\n

CyberArk

\n
Privileged Access Security (PTA)\n

CEF

\n
\n

Instructions

\n

Message format

\n
\n

Darktrace

\n
\n

Immune

\n
\n

CEF

\n
\n

See announcement. Contact vendor for instructions.

\n
\n

Digital Guardian

\n
\n

 

\n
\n

CEF

\n
\n

3rd party instructions

\n
\n

DocuSign

\n
\n

Monitor

\n
\n

Custom

\n
\n

See this blog post

\n
\n

Duo Security

\n
\n

 

\n
\n

CEF

\n
\n

Using Duo LogSync

\n
\n

Extrahop

\n
\n

Reveal

\n
\n

Built-in (CEF)

\n
\n

Instructions

\n
\n

F5

\n
\n

ASM (WAF)

\n
\n

Built-in (CEF)

\n
\n

Instructions

\n
\n

F5

\n
\n

BigIP (System, LTM, AFM, ASM, APM, AVR)

\n
\n

Built-in (Direct)

\n
\n

Instructions 

\n
\n

Fastly

\n
WAFCustom\n

See this blog post (Logic Apps or Azure Function)

\n
\n

Forcepoint

\n
Web Security (WebSense)CEF\n

Instructions

\n

Detailed reference

\n
\n

Forcepoint

\n
CASBCEF\n

Sentinel built-in connector

\n
\n

Forcepoint

\n
DLPDirect\n

Sentinel built-in connector

\n
\n

Forcepoint

\n
NGFWCEF\n

Sentinel built-in connector

\n
\n

Forescout

\n
CounterActCEF\n

Instructions

\n
\n

Fortinet

\n
 CEF\n

Sentinel built-in connector

\n

Log message reference

\n

CEF mapping and examples

\n
\n

Fortinet

\n
\n

FortiSIEM

\n
\n

CEF

\n
\n

Instructions

\n
\n

Fortinet

\n
\n

FortiSOAR

\n
\n

Integration

\n
\n

Instructions

\n
\n

GitHub

\n
\n

 

\n
\n

Custom

\n
\n

See connector, rules, and hunting queries 

\n

here

\n
\n

GCP

\n
\n

Cloud Storage

\n
\n

Logstash

\n
\n

See Plug-in. Use to get events stored in GCP Cloud Storage, not for Cloud Storage own audit events.

\n
\n

GCP

\n
\n

Pub/Sub

\n
\n

Logstash

\n
\n

See Plug-in. Use to get events sent using Pub/Sub, not for Pub/Sub own audit events.

\n
\n

GCP

\n
\n

Stacdriver

\n
\n

Logstash

\n

 

\n

Custom

\n
\n

Through GCP Cloud Storage or GCP Pub/Sub as described above. 

\n

Using GCP Cloud Function. See here.

\n
\n

Group-IB

\n
\n

 

\n
\n

Custom (TI Platform)

\n
\n

Using Logic Apps. See instructions

\n
\n

GuardiCore

\n
\n

Centra

\n
\n

CEF

\n
\n

Contact vendor for instructions

\n
\n

HP

\n
\n

Printers

\n
\n

Syslog

\n
\n

Instructions

\n
\n

IBM

\n
\n

iSeries

\n
\n

CEF

\n
\n

See here.

\n
\n

IBM

\n
\n

QRadar events

\n
\n

Syslog

\n
\n

Forward raw events or correlation events in raw, parsed, or JSON format. See instructions.

\n
\n

IBM

\n
\n

QRadar offenses

\n
\n

Custom (Function)

\n
\n

Blog post

\n
\n

IBM

\n
\n

X-Force

\n
\n

TI (TAXII)

\n
\n

Instructions

\n
\n

IBM

\n
\n

zSecure

\n
\n

CEF

\n
\n

See What's new for zSecure V2.3.0

\n

Note that it supports alerts only.

\n
\n

Illusive 

\n
\n

Attack Management System

\n
\n

Syslog

\n
\n

Sentinel built-in connector

\n
\n

Imperva

\n
\n

SecureSphere

\n
\n

CEF

\n
\n

Instructions

\n
InfobloxNIOS\n

Built-in (Syslog)

\n
\n

Instructions

\n
InSights \n

TI (TAXII)

\n
\n

TAXII Instructions and related workbook

\n
JamfPro\n

Syslog

\n
\n

Instructions

\n
JuniperATP\n

CEF

\n
\n

Instructions

\n
JuniperJunOS based devices\n

Built-in (Syslog)

\n
\n

Instructions

\n
KasperskySecurity Center CEFInstructions
\n

ManageEngine

\n
\n

AD Audit Plus

\n
\n

CEF

\n
\n

Instructions (use ArcSight instructions)

\n
\n

ManageEngine

\n
\n

Exchange Reporter Plus

\n
\n

Syslog

\n
\n

Instructions

\n
\n

McAfee

\n
\n

ePO

\n
\n

Syslog

\n
\n

Instructions (Note: TLS only (requires rsyslog TLS configuration)

\n
\n

McAfee

\n
\n

MVISION EDR

\n
\n

Syslog

\n
\n

Instructions

\n
\n

McAfee

\n
\n

Web Gateway

\n
\n

CEF

\n
\n

Instructions

\n
\n

Microfocus

\n
\n

Fortify AppDefender

\n
\n

CEF

\n
Instructions (require authentication; contact vendor for further details).
\n

Microsoft

\n
\n

Active Directory

\n
\n

Agent

\n
\n

Most AD events are logged as part of security events. 

\n

Also, See in this list:

\n
    \n
  • LDAP auditing
  • \n
  • SMBv1 auditing
  • \n
\n
\n

Microsoft

\n
\n

Advanced Threat Protection (ATA)

\n
\n

CEF

\n
\n\n
\n

Microsoft

\n
\n

Azure Active Directory (AAD)

\n
\n

Built-in (Diagnostics)

\n
\n\n
\n

Microsoft

\n
\n

Azure Active Directory Domain Services

\n
\n

Diagnostics

\n
\n\n
\n

Microsoft

\n
\n

Azure Active Directory Identity Protection

\n
\n

 

\n
\n\n
\n

Microsoft

\n
\n

Azure

\n

Azure Activity

\n

Azure Subscriptions

\n

Azure Management Groups

\n
\n

Direct

\n
\n\n
\n

Microsoft

\n
\n

Application Insights

\n
\n

Direct

\n
\n\n
\n

Microsoft

\n
App Services & Web Application monitoring \n

Direct

\n
Instructions and reference architecture 
\n

Microsoft

\n
\n

Azure B2B

\n
\n

Direct

\n
Included as part of AAD events
\n

Microsoft

\n
\n

Azure B2C

\n
\n

Direct

\n
collect B2C logs from your B2C tenant to your primary tenant AAD logs as described here
\n

Microsoft

\n
\n

Azure Cosmos DB

\n
\n

Direct

\n
Instructions
\n

Microsoft

\n
\n

Azure Data Lake Gen 1

\n
\n

Direct

\n
\n\n
\n

Microsoft

\n
\n

Azure Data Factory

\n
\n

Direct

\n
Instructions
\n

Microsoft

\n
\n

Azure Databricks

\n
\n

Direct

\n
Instructions
\n

Microsoft

\n
\n

Azure DDOS

\n
\n

Built-in (diagnostics)

\n
\n\n
MicrosoftAzure Defender  and Azure Security Center (ASC)\n

Direct

\n
\n\n
\n

Microsoft

\n
\n

Azure Defender for IoT

\n
\n

Built-in (Direct)

\n
\n\n
\n

Microsoft

\n
\n

Azure DevOps

\n
\n

Direct

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Azure Event Hub (subscription)

\n
\n

Logstash

\n
\n

See Logstash Plug-in. Use to get events sent using an Event Hub, not for Event Hub own audit events.

\n
\n

Microsoft

\n
\n

Azure Files

\n
\n

Direct (Diagnostics)

\n
\n

Instructions

\n

Schema information

\n
\n

Microsoft

\n
\n

Azure Firewall

\n
\n

Built-in (diagnostics)

\n
\n\n
\n

Microsoft

\n
\n

Azure Front Door

\n
\n

Direct

\n
Instructions
MicrosoftAzure Key Vault (AKV)\n

Built-in (Diagnostics)

\n
\n

Connect:

\n\n

Use:

\n\n
MicrosoftAzure Information Protection (Classic and Unified Labeling)\n

Built-in (Direct)

\n
Instructions
MicrosoftAzure Kubernetes Service (AKS)\n

Direct

\n
\n\n
MicrosoftAzure Log Analytics\n

Direct

\n
Collect query auditing and other metrics: Instructions
MicrosoftAzure Logic Apps\n

Direct

\n
Instructions
MicrosoftAzure Network Security Groups (NSG)\n

Direct

\n
\n\n
MicrosoftAzure SQL\n

Built-in (diagnostics)

\n
\n\n
MicrosoftAzure SQL Managed Instance\n

Direct

\n
Instructions
MicrosoftAzure Site Recovery\n

Direct

\n
Instructions
MicrosoftAzure Storage\n

Direct

\n
\n

Instructions

\n

Blog: Blob and File Storage Investigations

\n
MicrosoftAzure Storage Content\n

Custom (Azure Function)

\n
Ingest the content of Azure Storage Blobs. See GitHub.
MicrosoftAzure Synapse\n

Direct

\n
Instructions
MicrosoftAzure Web Application Firewall (WAF)\n

Built-in (Diagnostics)

\n
\n\n
\n

Microsoft

\n
\n

BitLocker / MBAM

\n
\n

Agent

\n
\n

Using Windows Event collection. Blog post

\n
\n

Microsoft

\n
\n

Cloud App Security (Alerts, Discovery logs)

\n
\n

Built-in (Direct)

\n
\n\n
\n

Microsoft

\n
\n

Cloud App Security (Activity Log)

\n
\n

CEF

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Defender for Office

\n
\n

Built-in

\n

Custom

\n

 

\n

 

\n

 

\n
\n

For AIRs alerts: instructions

\n

For other alerts: Use Either a Logic App or an Azure function custom connector. For the Azure Function connector, query for RecordType_d == \"28\", \"41\" or \"47\" .

\n
\n

Microsoft

\n
\n

Defender for Identity (Azure ATP) Alerts

\n
\n

Built-in

\n
\n\n
\n

Microsoft

\n
\n

Defender for Identity (Azure ATP) Events

\n
\n

CEF

\n
\n\n
\n

Microsoft

\n
\n

Desktop Analytics

\n
\n

Direct

\n
\n

Connect

\n
\n

Microsoft

\n
\n

DNS

\n
\n

Agent

\n
\n

Sentinel built-in connector

\n
\n

Microsoft

\n
\n

Dynamics 365

\n
\n

Built-in

\n
\n

Sentinel built-in connector

\n
\n

Microsoft

\n
\n

Dynamics (not 365)

\n
\n

Agent

\n
\n

Using IIS logs

\n

Using Dynamics Trace Files

\n
\n

Microsoft

\n
\n

IIS

\n
\n

Agent

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Intune

\n
\n

Direct

\n
\n

Connect

\n

Use cases

\n
\n

Microsoft

\n
\n

LDAP (Windows Server)

\n
\n

Agent

\n
\n

Configure AD diagnostics logging and set \"16 LDAP Interface Events\" to 2 or above.

\n
\n

Microsoft

\n
\n

Office 365 (Exchange, SharePoint, OneDrive, DLP Alerts)

\n
\n

Built-in

\n
\n

 

\n

Sentinel built-in connector

\n

For details about DLP alerts, read here

\n
\n

Microsoft 

\n
\n

Office 365 (Microsoft Defender for Office; formerly Office ATP, PowerBI, Yammer, Sway, Forms, eDiscovery, and others)

\n
\n

Custom (Azure Function, Logic Apps)

\n
\n

Use Either a Logic App or an Azure function custom connector

\n
\n

Microsoft

\n
\n

Office 365 e-mail trace logs

\n
\n

Custom (Logic Apps)

\n
\n

See Blog Post.

\n
\n

Microsoft

\n
\n

PowerBI Embedded

\n
\n

Direct (Diagnostics)

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

SMBv1 (Windows Server)

\n
\n

Agent

\n
\n

See Enable Auditing on SMB Servers, and the CmdLet reference 

\n
\n

Microsoft

\n
\n

Teams (Call Logs)

\n
\n

Custom

\n
\n

Using Logic Apps

\n
\n

Microsoft

\n
\n

Teams (Management Activity)

\n
\n

Built-in

\n
\n\n
\n

Microsoft

\n
\n

Teams Shifts

\n
\n

Custom

\n
\n

Use Either a Logic App or an Azure function custom connector. For the Azure Function connector, query for RecordType_d == \"73\"

\n
\n

Microsoft

\n
\n

SCCM

\n
\n

Agent

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

SQL Server

\n
\n

Agent

\n
\n

Instructions, parser, rules, and hunting queries

\n

You can also audit at the engine level.

\n
\n

Microsoft

\n
\n

Sysmon

\n
\n

Agent

\n
\n

Using Windows Event collection. Blog post

\n
\n

Microsoft

\n
\n

Windows (Security Events)

\n
\n

Agent

\n
\n\n
\n

Microsoft

\n
\n

Windows (Other Events, Sysmon)

\n
\n

Agent

\n
\n

Instructions

\n
\n

Microsoft

\n
\n

Windows network connections

\n
\n

Agent

\n
\n

VM Insights

\n

Wire Data

\n
\n

Microsoft

\n
\n

Windows Firewall

\n
\n

Agent

\n
Sentinel built-in connector
\n

Microsoft

\n
\n

Windows Virtual Desktop

\n
\n

Direct

\n
\n\n
\n

Mimecast

\n
\n

 

\n
\n

Agent

\n
\n

Announcement. For technical instructions, contact the vendor.

\n
\n

Minerva Labs

\n
\n

 

\n
\n

CEF

\n
\n

Please ask the vendor for instructions.

\n
\n

MISP

\n
\n

 

\n
\n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
\n

NetApp

\n
\n

ONTAP

\n
\n

Syslog

\n
\n

Instructions

\n

Note that those are management activity audit logs and not file usage activity logs.

\n
\n

Netflow

\n
\n

 

\n
\n

Logstash

\n
\n

Use the Netflow codec plug-in

\n
\n

Nexthink

\n
\n

 

\n
\n

CEF

\n
\n

Instructions

\n
\n

Nozomi

\n
\n

Guardian

\n
\n

CEF

\n
\n

Contact vendor for details

\n
\n

NXlog

\n
\n

 

\n
\n

Direct

\n
\n

Instructions

\n
\n

Okta

\n
\n

SSO

\n
\n

Built-in (Function)

\n
\n

Instructions

\n
\n

One Identity

\n
\n

Safeguard

\n
\n

Built-in (CEF)

\n
\n

Instructions

\n
\n

Oracle

\n
\n

Cloud (OCI)

\n
\n

Custom (Azure Function)

\n
Available Here
\n

Oracle

\n
\n

DB

\n
\n

Syslog

\n
\n

Instructions

\n
\n

Orca

\n
\n

 

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

OSSEC

\n
\n

 

\n
\n

CEF

\n
\n

Instructions

\n
\n

Pager Duty

\n
\n

 

\n
\n

Automation (Playbook)

\n
\n

Blog post

\n
\n

Palo Alto

\n
\n

Cloudgenix

\n
\n

Syslog

\n
\n

Instructions

\n
\n

Palo Alto

\n
\n

Minemeld

\n
\n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
\n

Palo Alto

\n
\n

PanOS

\n
\n

CEF

\n
\n

Sentinel built-in connector

\n
\n

Palo Alto

\n
\n

Panorama

\n
\n

CEF

\n
\n

Instructions

\n
\n

Palo Alto

\n
\n

Prisma

\n
\n

Syslog

\n

Custom

\n
\n

Instructions, Fields

\n

Logic Apps using a Webhook and clarification

\n
\n

Palo Alto

\n
\n

Traps through Cortex

\n
\n

Syslog

\n
\n

Instructions

\n

Notes:

\n

- Require rsyslog configuration to support RFC5424

\n

- TLS only (requires rsyslog TLS configuration)

\n

- The certificate has to be signed by a public CA

\n
\n

Palo Alto

\n
\n

XDR

\n
\n

CEF

\n
\n

Instructions

\n
\n

Palo Alto

\n
\n

XSOAR

\n
\n

Integration

\n
\n

Forward Azure Sentinel incidents to Palo Alto XSOAR 

\n
\n

Perimeter 81

\n
\n

 

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Ping Identity

\n
\n

Federate

\n
\n

CEF

\n
\n

Instructions

\n
\n

Ping Identity

\n
\n

Provisioner

\n
\n

CEF

\n
\n

Instructions

\n
PostgressDBSyslog, Windows Event log\n

Instructions

\n
ProofpointOn DemandBuilt-in (API)\n

Instructions

\n
ProofpointTAPBuilt-in (Function)\n

Instructions

\n
PulseConnectBuilt-in (Syslog)\n

Instructions

\n
QualysVMBuilt-in (Function)\n

Instructions

\n
RadwareCloud WAFLogstash\n

Instructions

\n
RedHatOpenShiftSyslog
API
\n

Instructions for Syslog
Fluentd Log Analytics plugin for API

\n
RedHatAzure OpenShiftSyslog
Custom
\n

Instructions for Syslog
Fluentd Log Analytics plugin for API

\n
RiskIQ Action (Logic Apps)\n

Azure Logic-Apps built-in connector

\n
SalesforceService CloudBuilt-in (Function)\n

Instructions

\n
SAPHanaSyslog\n

Instructions (requires an SAP account)

\n
SentinelOne CEF\n

Please consult the vendor for instructions

\n
SNMP Syslog\n

Instructions

\n
Snort Agent\n

Instructions

\n
SonicWall CEF\n

Instructions

\n

Make sure you:
- Select local use 4 as the facility.

\n

- Select ArcSight as the Syslog format.

\n
SophosCentralCEFInstructions. Note that the script provided by Sophos has to be scheduled using a cron job, which is not documented on the reference page.
SophosXF FirewallBuilt-in (Syslog)Instructions
Squadra  secRMMBuilt-in (API)Instructions
Squid Proxy \n

Built-in (Agent)

\n

Syslog

\n
\n

Instructions

\n

 

\n

Configure access logs with either the TCP or UDP modules. Sentinel's built-in queries use the default log format.

\n
\n

Symantec

\n
\n

DLP

\n
\n

Syslog

\n

CEF

\n
\n

Instructions. Note that only UDP is supported

\n

Instructions. Uses response automation.

\n
\n

Symantec

\n
\n

ICDX

\n
\n

Built-in (API)

\n
\n

Instructions

\n
\n

Symantec

\n
\n

Proxy SG (Bluecoat)

\n
\n

Built-in (Syslog)

\n
\n

Instructions

\n
Symantec  Endpoint Protection ManagerSyslogInstructions  
SymantecCloud Workload ProtectionAPIInstructions
SymantecVIPBuilt-in (Syslog)Instructions
TheHive \n

Integration

\n
\n

Send new incidents to TheHive

\n
ThinkstCanary\n

Syslog

\n
\n

Instructions

\n
ThreatConnect \n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
ThreatQuotient \n

TI (Platform)

\n
\n

Sentinel built-in connector

\n
ThycoticSecret Server\n

CEF

\n
\n

Instructions

\n
TitanHQWebTitan Cloud\n

Syslog

\n
\n

Instructions

\n
Trend Micro \n

CEF

\n
\n

Using Control Manager

\n

Using LogForwarder

\n
Trend MicroApax Central (Cloud and On-prem)\n

CEF

\n
\n

Instructions

\n
Trend MicroDeep Security\n

CEF

\n
\n

Sentinel built-in connector

\n
TufinSecureTrack\n

Syslog

\n
\n

Instructions

\n
\n

Varonis

\n
\n

DatAlert

\n
\n

CEF

\n
\n

Instructions

\n
WatchGuard CEFInstructions
Zimperium  
Mobile Threat DefenseBuilt-in (API)Instructions 
zScalerInternet Access (ZIA)Built-in (CEF)Instructions
zScalerPrivate Access (ZPA)LogstashUse LSS. Since LSS sends raw TCP but not Syslog, you will have to use Logstash and not Azure Sentinel's native connector. 
Zoom CustomUsing Azure Function. See blog post.
\n

 

","kudosSumWeight":12,"postTime":"2019-08-13T23:53:54.271-07:00","images":{"__typename":"AssociatedImageConnection","edges":[],"totalCount":0,"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"attachments":{"__typename":"AttachmentConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"tags":{"__typename":"TagConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[{"__typename":"TagEdge","cursor":"MjUuMXwyLjF8b3wxMHxfTlZffDE","node":{"__typename":"Tag","id":"tag:Connectors","text":"Connectors","time":"2017-10-25T02:38:20.817-07:00","lastActivityTime":null,"messagesCount":null,"followersCount":null}}]},"timeToRead":12,"rawTeaser":"

Want to connect a source system to Sentinel to send events? Even if not on the official source list, this is probably supported, and if not a custom community solution is avaliable. Here you can find information about it.

","introduction":"","coverImage":null,"coverImageProperties":{"__typename":"CoverImageProperties","style":"STANDARD","titlePosition":"BOTTOM","altText":""},"currentRevision":{"__ref":"Revision:revision:803891_173"},"latestVersion":{"__typename":"FriendlyVersion","major":"171","minor":"0"},"metrics":{"__typename":"MessageMetrics","views":221435},"visibilityScope":"PUBLIC","canonicalUrl":null,"seoTitle":null,"seoDescription":null,"placeholder":false,"originalMessageForPlaceholder":null,"contributors":{"__typename":"UserConnection","edges":[]},"nonCoAuthorContributors":{"__typename":"UserConnection","edges":[]},"coAuthors":{"__typename":"UserConnection","edges":[]},"blogMessagePolicies":{"__typename":"BlogMessagePolicies","canDoAuthoringActionsOnBlog":{"__typename":"PolicyResult","failureReason":{"__typename":"FailureReason","message":"error.lithium.policies.blog.action_can_do_authoring_action.accessDenied","key":"error.lithium.policies.blog.action_can_do_authoring_action.accessDenied","args":[]}}},"archivalData":null,"replies":{"__typename":"MessageConnection","edges":[{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwzNzc5Njkx","node":{"__ref":"BlogReplyMessage:message:3779691"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwzNDQwNDE3","node":{"__ref":"BlogReplyMessage:message:3440417"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyNzk1MjE4","node":{"__ref":"BlogReplyMessage:message:2795218"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyNzk0MDA2","node":{"__ref":"BlogReplyMessage:message:2794006"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyNjQxNTUz","node":{"__ref":"BlogReplyMessage:message:2641553"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyNTI3OTE2","node":{"__ref":"BlogReplyMessage:message:2527916"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyNDY5NTg3","node":{"__ref":"BlogReplyMessage:message:2469587"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyMzY2NzM3","node":{"__ref":"BlogReplyMessage:message:2366737"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyMzIxODU3","node":{"__ref":"BlogReplyMessage:message:2321857"}},{"__typename":"MessageEdge","cursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyMzIxNjMw","node":{"__ref":"BlogReplyMessage:message:2321630"}}],"pageInfo":{"__typename":"PageInfo","hasNextPage":true,"endCursor":"MjUuMXwyLjF8aXwxMHwxMzI6MHxpbnQsMzc3OTY5MSwyMzIxNjMw","hasPreviousPage":false,"startCursor":null}},"customFields":[],"revisions({\"constraints\":{\"isPublished\":{\"eq\":true}},\"first\":1})":{"__typename":"RevisionConnection","totalCount":173}},"Conversation:conversation:803891":{"__typename":"Conversation","id":"conversation:803891","solved":false,"topic":{"__ref":"BlogTopicMessage:message:803891"},"lastPostingActivityTime":"2023-03-27T06:17:58.427-07:00","lastPostTime":"2023-03-27T06:17:58.427-07:00","unreadReplyCount":78,"isSubscribed":false},"ModerationData:moderation_data:803891":{"__typename":"ModerationData","id":"moderation_data:803891","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"Revision:revision:803891_173":{"__typename":"Revision","id":"revision:803891_173","lastEditTime":"2021-09-29T23:29:59.830-07:00"},"CachedAsset:theme:customTheme1-1744326567449":{"__typename":"CachedAsset","id":"theme:customTheme1-1744326567449","value":{"id":"customTheme1","animation":{"fast":"150ms","normal":"250ms","slow":"500ms","slowest":"750ms","function":"cubic-bezier(0.07, 0.91, 0.51, 1)","__typename":"AnimationThemeSettings"},"avatar":{"borderRadius":"50%","collections":["default"],"__typename":"AvatarThemeSettings"},"basics":{"browserIcon":{"imageAssetName":"favicon-1730836283320.png","imageLastModified":"1730836286415","__typename":"ThemeAsset"},"customerLogo":{"imageAssetName":"favicon-1730836271365.png","imageLastModified":"1730836274203","__typename":"ThemeAsset"},"maximumWidthOfPageContent":"1300px","oneColumnNarrowWidth":"800px","gridGutterWidthMd":"30px","gridGutterWidthXs":"10px","pageWidthStyle":"WIDTH_OF_BROWSER","__typename":"BasicsThemeSettings"},"buttons":{"borderRadiusSm":"3px","borderRadius":"3px","borderRadiusLg":"5px","paddingY":"5px","paddingYLg":"7px","paddingYHero":"var(--lia-bs-btn-padding-y-lg)","paddingX":"12px","paddingXLg":"16px","paddingXHero":"60px","fontStyle":"NORMAL","fontWeight":"700","textTransform":"NONE","disabledOpacity":0.5,"primaryTextColor":"var(--lia-bs-white)","primaryTextHoverColor":"var(--lia-bs-white)","primaryTextActiveColor":"var(--lia-bs-white)","primaryBgColor":"var(--lia-bs-primary)","primaryBgHoverColor":"hsl(var(--lia-bs-primary-h), var(--lia-bs-primary-s), calc(var(--lia-bs-primary-l) * 0.85))","primaryBgActiveColor":"hsl(var(--lia-bs-primary-h), var(--lia-bs-primary-s), calc(var(--lia-bs-primary-l) * 0.7))","primaryBorder":"1px solid transparent","primaryBorderHover":"1px solid transparent","primaryBorderActive":"1px solid transparent","primaryBorderFocus":"1px solid var(--lia-bs-white)","primaryBoxShadowFocus":"0 0 0 1px var(--lia-bs-primary), 0 0 0 4px hsla(var(--lia-bs-primary-h), var(--lia-bs-primary-s), var(--lia-bs-primary-l), 0.2)","secondaryTextColor":"var(--lia-bs-gray-900)","secondaryTextHoverColor":"hsl(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), calc(var(--lia-bs-gray-900-l) * 0.95))","secondaryTextActiveColor":"hsl(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), calc(var(--lia-bs-gray-900-l) * 0.9))","secondaryBgColor":"var(--lia-bs-gray-200)","secondaryBgHoverColor":"hsl(var(--lia-bs-gray-200-h), var(--lia-bs-gray-200-s), calc(var(--lia-bs-gray-200-l) * 0.96))","secondaryBgActiveColor":"hsl(var(--lia-bs-gray-200-h), var(--lia-bs-gray-200-s), calc(var(--lia-bs-gray-200-l) * 0.92))","secondaryBorder":"1px solid transparent","secondaryBorderHover":"1px solid transparent","secondaryBorderActive":"1px solid transparent","secondaryBorderFocus":"1px solid transparent","secondaryBoxShadowFocus":"0 0 0 1px var(--lia-bs-primary), 0 0 0 4px hsla(var(--lia-bs-primary-h), var(--lia-bs-primary-s), var(--lia-bs-primary-l), 0.2)","tertiaryTextColor":"var(--lia-bs-gray-900)","tertiaryTextHoverColor":"hsl(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), calc(var(--lia-bs-gray-900-l) * 0.95))","tertiaryTextActiveColor":"hsl(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), calc(var(--lia-bs-gray-900-l) * 0.9))","tertiaryBgColor":"transparent","tertiaryBgHoverColor":"transparent","tertiaryBgActiveColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.04)","tertiaryBorder":"1px solid transparent","tertiaryBorderHover":"1px solid hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.08)","tertiaryBorderActive":"1px solid transparent","tertiaryBorderFocus":"1px solid transparent","tertiaryBoxShadowFocus":"0 0 0 1px var(--lia-bs-primary), 0 0 0 4px hsla(var(--lia-bs-primary-h), var(--lia-bs-primary-s), var(--lia-bs-primary-l), 0.2)","destructiveTextColor":"var(--lia-bs-danger)","destructiveTextHoverColor":"hsl(var(--lia-bs-danger-h), var(--lia-bs-danger-s), calc(var(--lia-bs-danger-l) * 0.95))","destructiveTextActiveColor":"hsl(var(--lia-bs-danger-h), var(--lia-bs-danger-s), calc(var(--lia-bs-danger-l) * 0.9))","destructiveBgColor":"var(--lia-bs-gray-200)","destructiveBgHoverColor":"hsl(var(--lia-bs-gray-200-h), var(--lia-bs-gray-200-s), calc(var(--lia-bs-gray-200-l) * 0.96))","destructiveBgActiveColor":"hsl(var(--lia-bs-gray-200-h), var(--lia-bs-gray-200-s), calc(var(--lia-bs-gray-200-l) * 0.92))","destructiveBorder":"1px solid transparent","destructiveBorderHover":"1px solid transparent","destructiveBorderActive":"1px solid transparent","destructiveBorderFocus":"1px solid transparent","destructiveBoxShadowFocus":"0 0 0 1px var(--lia-bs-primary), 0 0 0 4px hsla(var(--lia-bs-primary-h), var(--lia-bs-primary-s), var(--lia-bs-primary-l), 0.2)","__typename":"ButtonsThemeSettings"},"border":{"color":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.08)","mainContent":"NONE","sideContent":"LIGHT","radiusSm":"3px","radius":"5px","radiusLg":"9px","radius50":"100vw","__typename":"BorderThemeSettings"},"boxShadow":{"xs":"0 0 0 1px hsla(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), var(--lia-bs-gray-900-l), 0.08), 0 3px 0 -1px hsla(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), var(--lia-bs-gray-900-l), 0.16)","sm":"0 2px 4px hsla(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), var(--lia-bs-gray-900-l), 0.12)","md":"0 5px 15px hsla(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), var(--lia-bs-gray-900-l), 0.3)","lg":"0 10px 30px hsla(var(--lia-bs-gray-900-h), var(--lia-bs-gray-900-s), var(--lia-bs-gray-900-l), 0.3)","__typename":"BoxShadowThemeSettings"},"cards":{"bgColor":"var(--lia-panel-bg-color)","borderRadius":"var(--lia-panel-border-radius)","boxShadow":"var(--lia-box-shadow-xs)","__typename":"CardsThemeSettings"},"chip":{"maxWidth":"300px","height":"30px","__typename":"ChipThemeSettings"},"coreTypes":{"defaultMessageLinkColor":"var(--lia-bs-link-color)","defaultMessageLinkDecoration":"none","defaultMessageLinkFontStyle":"NORMAL","defaultMessageLinkFontWeight":"400","defaultMessageFontStyle":"NORMAL","defaultMessageFontWeight":"400","forumColor":"#4099E2","forumFontFamily":"var(--lia-bs-font-family-base)","forumFontWeight":"var(--lia-default-message-font-weight)","forumLineHeight":"var(--lia-bs-line-height-base)","forumFontStyle":"var(--lia-default-message-font-style)","forumMessageLinkColor":"var(--lia-default-message-link-color)","forumMessageLinkDecoration":"var(--lia-default-message-link-decoration)","forumMessageLinkFontStyle":"var(--lia-default-message-link-font-style)","forumMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","forumSolvedColor":"#148563","blogColor":"#1CBAA0","blogFontFamily":"var(--lia-bs-font-family-base)","blogFontWeight":"var(--lia-default-message-font-weight)","blogLineHeight":"1.75","blogFontStyle":"var(--lia-default-message-font-style)","blogMessageLinkColor":"var(--lia-default-message-link-color)","blogMessageLinkDecoration":"var(--lia-default-message-link-decoration)","blogMessageLinkFontStyle":"var(--lia-default-message-link-font-style)","blogMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","tkbColor":"#4C6B90","tkbFontFamily":"var(--lia-bs-font-family-base)","tkbFontWeight":"var(--lia-default-message-font-weight)","tkbLineHeight":"1.75","tkbFontStyle":"var(--lia-default-message-font-style)","tkbMessageLinkColor":"var(--lia-default-message-link-color)","tkbMessageLinkDecoration":"var(--lia-default-message-link-decoration)","tkbMessageLinkFontStyle":"var(--lia-default-message-link-font-style)","tkbMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","qandaColor":"#4099E2","qandaFontFamily":"var(--lia-bs-font-family-base)","qandaFontWeight":"var(--lia-default-message-font-weight)","qandaLineHeight":"var(--lia-bs-line-height-base)","qandaFontStyle":"var(--lia-default-message-link-font-style)","qandaMessageLinkColor":"var(--lia-default-message-link-color)","qandaMessageLinkDecoration":"var(--lia-default-message-link-decoration)","qandaMessageLinkFontStyle":"var(--lia-default-message-link-font-style)","qandaMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","qandaSolvedColor":"#3FA023","ideaColor":"#FF8000","ideaFontFamily":"var(--lia-bs-font-family-base)","ideaFontWeight":"var(--lia-default-message-font-weight)","ideaLineHeight":"var(--lia-bs-line-height-base)","ideaFontStyle":"var(--lia-default-message-font-style)","ideaMessageLinkColor":"var(--lia-default-message-link-color)","ideaMessageLinkDecoration":"var(--lia-default-message-link-decoration)","ideaMessageLinkFontStyle":"var(--lia-default-message-link-font-style)","ideaMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","contestColor":"#FCC845","contestFontFamily":"var(--lia-bs-font-family-base)","contestFontWeight":"var(--lia-default-message-font-weight)","contestLineHeight":"var(--lia-bs-line-height-base)","contestFontStyle":"var(--lia-default-message-link-font-style)","contestMessageLinkColor":"var(--lia-default-message-link-color)","contestMessageLinkDecoration":"var(--lia-default-message-link-decoration)","contestMessageLinkFontStyle":"ITALIC","contestMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","occasionColor":"#D13A1F","occasionFontFamily":"var(--lia-bs-font-family-base)","occasionFontWeight":"var(--lia-default-message-font-weight)","occasionLineHeight":"var(--lia-bs-line-height-base)","occasionFontStyle":"var(--lia-default-message-font-style)","occasionMessageLinkColor":"var(--lia-default-message-link-color)","occasionMessageLinkDecoration":"var(--lia-default-message-link-decoration)","occasionMessageLinkFontStyle":"var(--lia-default-message-link-font-style)","occasionMessageLinkFontWeight":"var(--lia-default-message-link-font-weight)","grouphubColor":"#333333","categoryColor":"#949494","communityColor":"#FFFFFF","productColor":"#949494","__typename":"CoreTypesThemeSettings"},"colors":{"black":"#000000","white":"#FFFFFF","gray100":"#F7F7F7","gray200":"#F7F7F7","gray300":"#E8E8E8","gray400":"#D9D9D9","gray500":"#CCCCCC","gray600":"#717171","gray700":"#707070","gray800":"#545454","gray900":"#333333","dark":"#545454","light":"#F7F7F7","primary":"#0069D4","secondary":"#333333","bodyText":"#1E1E1E","bodyBg":"#FFFFFF","info":"#409AE2","success":"#41C5AE","warning":"#FCC844","danger":"#BC341B","alertSystem":"#FF6600","textMuted":"#707070","highlight":"#FFFCAD","outline":"var(--lia-bs-primary)","custom":["#D3F5A4","#243A5E"],"__typename":"ColorsThemeSettings"},"divider":{"size":"3px","marginLeft":"4px","marginRight":"4px","borderRadius":"50%","bgColor":"var(--lia-bs-gray-600)","bgColorActive":"var(--lia-bs-gray-600)","__typename":"DividerThemeSettings"},"dropdown":{"fontSize":"var(--lia-bs-font-size-sm)","borderColor":"var(--lia-bs-border-color)","borderRadius":"var(--lia-bs-border-radius-sm)","dividerBg":"var(--lia-bs-gray-300)","itemPaddingY":"5px","itemPaddingX":"20px","headerColor":"var(--lia-bs-gray-700)","__typename":"DropdownThemeSettings"},"email":{"link":{"color":"#0069D4","hoverColor":"#0061c2","decoration":"none","hoverDecoration":"underline","__typename":"EmailLinkSettings"},"border":{"color":"#e4e4e4","__typename":"EmailBorderSettings"},"buttons":{"borderRadiusLg":"5px","paddingXLg":"16px","paddingYLg":"7px","fontWeight":"700","primaryTextColor":"#ffffff","primaryTextHoverColor":"#ffffff","primaryBgColor":"#0069D4","primaryBgHoverColor":"#005cb8","primaryBorder":"1px solid transparent","primaryBorderHover":"1px solid transparent","__typename":"EmailButtonsSettings"},"panel":{"borderRadius":"5px","borderColor":"#e4e4e4","__typename":"EmailPanelSettings"},"__typename":"EmailThemeSettings"},"emoji":{"skinToneDefault":"#ffcd43","skinToneLight":"#fae3c5","skinToneMediumLight":"#e2cfa5","skinToneMedium":"#daa478","skinToneMediumDark":"#a78058","skinToneDark":"#5e4d43","__typename":"EmojiThemeSettings"},"heading":{"color":"var(--lia-bs-body-color)","fontFamily":"Segoe UI","fontStyle":"NORMAL","fontWeight":"400","h1FontSize":"34px","h2FontSize":"32px","h3FontSize":"28px","h4FontSize":"24px","h5FontSize":"20px","h6FontSize":"16px","lineHeight":"1.3","subHeaderFontSize":"11px","subHeaderFontWeight":"500","h1LetterSpacing":"normal","h2LetterSpacing":"normal","h3LetterSpacing":"normal","h4LetterSpacing":"normal","h5LetterSpacing":"normal","h6LetterSpacing":"normal","subHeaderLetterSpacing":"2px","h1FontWeight":"var(--lia-bs-headings-font-weight)","h2FontWeight":"var(--lia-bs-headings-font-weight)","h3FontWeight":"var(--lia-bs-headings-font-weight)","h4FontWeight":"var(--lia-bs-headings-font-weight)","h5FontWeight":"var(--lia-bs-headings-font-weight)","h6FontWeight":"var(--lia-bs-headings-font-weight)","__typename":"HeadingThemeSettings"},"icons":{"size10":"10px","size12":"12px","size14":"14px","size16":"16px","size20":"20px","size24":"24px","size30":"30px","size40":"40px","size50":"50px","size60":"60px","size80":"80px","size120":"120px","size160":"160px","__typename":"IconsThemeSettings"},"imagePreview":{"bgColor":"var(--lia-bs-gray-900)","titleColor":"var(--lia-bs-white)","controlColor":"var(--lia-bs-white)","controlBgColor":"var(--lia-bs-gray-800)","__typename":"ImagePreviewThemeSettings"},"input":{"borderColor":"var(--lia-bs-gray-600)","disabledColor":"var(--lia-bs-gray-600)","focusBorderColor":"var(--lia-bs-primary)","labelMarginBottom":"10px","btnFontSize":"var(--lia-bs-font-size-sm)","focusBoxShadow":"0 0 0 3px hsla(var(--lia-bs-primary-h), var(--lia-bs-primary-s), var(--lia-bs-primary-l), 0.2)","checkLabelMarginBottom":"2px","checkboxBorderRadius":"3px","borderRadiusSm":"var(--lia-bs-border-radius-sm)","borderRadius":"var(--lia-bs-border-radius)","borderRadiusLg":"var(--lia-bs-border-radius-lg)","formTextMarginTop":"4px","textAreaBorderRadius":"var(--lia-bs-border-radius)","activeFillColor":"var(--lia-bs-primary)","__typename":"InputThemeSettings"},"loading":{"dotDarkColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.2)","dotLightColor":"hsla(var(--lia-bs-white-h), var(--lia-bs-white-s), var(--lia-bs-white-l), 0.5)","barDarkColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.06)","barLightColor":"hsla(var(--lia-bs-white-h), var(--lia-bs-white-s), var(--lia-bs-white-l), 0.4)","__typename":"LoadingThemeSettings"},"link":{"color":"var(--lia-bs-primary)","hoverColor":"hsl(var(--lia-bs-primary-h), var(--lia-bs-primary-s), calc(var(--lia-bs-primary-l) - 10%))","decoration":"none","hoverDecoration":"underline","__typename":"LinkThemeSettings"},"listGroup":{"itemPaddingY":"15px","itemPaddingX":"15px","borderColor":"var(--lia-bs-gray-300)","__typename":"ListGroupThemeSettings"},"modal":{"contentTextColor":"var(--lia-bs-body-color)","contentBg":"var(--lia-bs-white)","backgroundBg":"var(--lia-bs-black)","smSize":"440px","mdSize":"760px","lgSize":"1080px","backdropOpacity":0.3,"contentBoxShadowXs":"var(--lia-bs-box-shadow-sm)","contentBoxShadow":"var(--lia-bs-box-shadow)","headerFontWeight":"700","__typename":"ModalThemeSettings"},"navbar":{"position":"FIXED","background":{"attachment":null,"clip":null,"color":"var(--lia-bs-white)","imageAssetName":"","imageLastModified":"0","origin":null,"position":"CENTER_CENTER","repeat":"NO_REPEAT","size":"COVER","__typename":"BackgroundProps"},"backgroundOpacity":0.8,"paddingTop":"15px","paddingBottom":"15px","borderBottom":"1px solid var(--lia-bs-border-color)","boxShadow":"var(--lia-bs-box-shadow-sm)","brandMarginRight":"30px","brandMarginRightSm":"10px","brandLogoHeight":"30px","linkGap":"10px","linkJustifyContent":"flex-start","linkPaddingY":"5px","linkPaddingX":"10px","linkDropdownPaddingY":"9px","linkDropdownPaddingX":"var(--lia-nav-link-px)","linkColor":"var(--lia-bs-body-color)","linkHoverColor":"var(--lia-bs-primary)","linkFontSize":"var(--lia-bs-font-size-sm)","linkFontStyle":"NORMAL","linkFontWeight":"400","linkTextTransform":"NONE","linkLetterSpacing":"normal","linkBorderRadius":"var(--lia-bs-border-radius-sm)","linkBgColor":"transparent","linkBgHoverColor":"transparent","linkBorder":"none","linkBorderHover":"none","linkBoxShadow":"none","linkBoxShadowHover":"none","linkTextBorderBottom":"none","linkTextBorderBottomHover":"none","dropdownPaddingTop":"10px","dropdownPaddingBottom":"15px","dropdownPaddingX":"10px","dropdownMenuOffset":"2px","dropdownDividerMarginTop":"10px","dropdownDividerMarginBottom":"10px","dropdownBorderColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.08)","controllerBgHoverColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.1)","controllerIconColor":"var(--lia-bs-body-color)","controllerIconHoverColor":"var(--lia-bs-body-color)","controllerTextColor":"var(--lia-nav-controller-icon-color)","controllerTextHoverColor":"var(--lia-nav-controller-icon-hover-color)","controllerHighlightColor":"hsla(30, 100%, 50%)","controllerHighlightTextColor":"var(--lia-yiq-light)","controllerBorderRadius":"var(--lia-border-radius-50)","hamburgerColor":"var(--lia-nav-controller-icon-color)","hamburgerHoverColor":"var(--lia-nav-controller-icon-color)","hamburgerBgColor":"transparent","hamburgerBgHoverColor":"transparent","hamburgerBorder":"none","hamburgerBorderHover":"none","collapseMenuMarginLeft":"20px","collapseMenuDividerBg":"var(--lia-nav-link-color)","collapseMenuDividerOpacity":0.16,"__typename":"NavbarThemeSettings"},"pager":{"textColor":"var(--lia-bs-link-color)","textFontWeight":"var(--lia-font-weight-md)","textFontSize":"var(--lia-bs-font-size-sm)","__typename":"PagerThemeSettings"},"panel":{"bgColor":"var(--lia-bs-white)","borderRadius":"var(--lia-bs-border-radius)","borderColor":"var(--lia-bs-border-color)","boxShadow":"none","__typename":"PanelThemeSettings"},"popover":{"arrowHeight":"8px","arrowWidth":"16px","maxWidth":"300px","minWidth":"100px","headerBg":"var(--lia-bs-white)","borderColor":"var(--lia-bs-border-color)","borderRadius":"var(--lia-bs-border-radius)","boxShadow":"0 0.5rem 1rem hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.15)","__typename":"PopoverThemeSettings"},"prism":{"color":"#000000","bgColor":"#f5f2f0","fontFamily":"var(--font-family-monospace)","fontSize":"var(--lia-bs-font-size-base)","fontWeightBold":"var(--lia-bs-font-weight-bold)","fontStyleItalic":"italic","tabSize":2,"highlightColor":"#b3d4fc","commentColor":"#62707e","punctuationColor":"#6f6f6f","namespaceOpacity":"0.7","propColor":"#990055","selectorColor":"#517a00","operatorColor":"#906736","operatorBgColor":"hsla(0, 0%, 100%, 0.5)","keywordColor":"#0076a9","functionColor":"#d3284b","variableColor":"#c14700","__typename":"PrismThemeSettings"},"rte":{"bgColor":"var(--lia-bs-white)","borderRadius":"var(--lia-panel-border-radius)","boxShadow":" var(--lia-panel-box-shadow)","customColor1":"#bfedd2","customColor2":"#fbeeb8","customColor3":"#f8cac6","customColor4":"#eccafa","customColor5":"#c2e0f4","customColor6":"#2dc26b","customColor7":"#f1c40f","customColor8":"#e03e2d","customColor9":"#b96ad9","customColor10":"#3598db","customColor11":"#169179","customColor12":"#e67e23","customColor13":"#ba372a","customColor14":"#843fa1","customColor15":"#236fa1","customColor16":"#ecf0f1","customColor17":"#ced4d9","customColor18":"#95a5a6","customColor19":"#7e8c8d","customColor20":"#34495e","customColor21":"#000000","customColor22":"#ffffff","defaultMessageHeaderMarginTop":"40px","defaultMessageHeaderMarginBottom":"20px","defaultMessageItemMarginTop":"0","defaultMessageItemMarginBottom":"10px","diffAddedColor":"hsla(170, 53%, 51%, 0.4)","diffChangedColor":"hsla(43, 97%, 63%, 0.4)","diffNoneColor":"hsla(0, 0%, 80%, 0.4)","diffRemovedColor":"hsla(9, 74%, 47%, 0.4)","specialMessageHeaderMarginTop":"40px","specialMessageHeaderMarginBottom":"20px","specialMessageItemMarginTop":"0","specialMessageItemMarginBottom":"10px","__typename":"RteThemeSettings"},"tags":{"bgColor":"var(--lia-bs-gray-200)","bgHoverColor":"var(--lia-bs-gray-400)","borderRadius":"var(--lia-bs-border-radius-sm)","color":"var(--lia-bs-body-color)","hoverColor":"var(--lia-bs-body-color)","fontWeight":"var(--lia-font-weight-md)","fontSize":"var(--lia-font-size-xxs)","textTransform":"UPPERCASE","letterSpacing":"0.5px","__typename":"TagsThemeSettings"},"toasts":{"borderRadius":"var(--lia-bs-border-radius)","paddingX":"12px","__typename":"ToastsThemeSettings"},"typography":{"fontFamilyBase":"Segoe UI","fontStyleBase":"NORMAL","fontWeightBase":"400","fontWeightLight":"300","fontWeightNormal":"400","fontWeightMd":"500","fontWeightBold":"700","letterSpacingSm":"normal","letterSpacingXs":"normal","lineHeightBase":"1.5","fontSizeBase":"16px","fontSizeXxs":"11px","fontSizeXs":"12px","fontSizeSm":"14px","fontSizeLg":"20px","fontSizeXl":"24px","smallFontSize":"14px","customFonts":[{"source":"SERVER","name":"Segoe UI","styles":[{"style":"NORMAL","weight":"400","__typename":"FontStyleData"},{"style":"NORMAL","weight":"300","__typename":"FontStyleData"},{"style":"NORMAL","weight":"600","__typename":"FontStyleData"},{"style":"NORMAL","weight":"700","__typename":"FontStyleData"},{"style":"ITALIC","weight":"400","__typename":"FontStyleData"}],"assetNames":["SegoeUI-normal-400.woff2","SegoeUI-normal-300.woff2","SegoeUI-normal-600.woff2","SegoeUI-normal-700.woff2","SegoeUI-italic-400.woff2"],"__typename":"CustomFont"},{"source":"SERVER","name":"MWF Fluent Icons","styles":[{"style":"NORMAL","weight":"400","__typename":"FontStyleData"}],"assetNames":["MWFFluentIcons-normal-400.woff2"],"__typename":"CustomFont"}],"__typename":"TypographyThemeSettings"},"unstyledListItem":{"marginBottomSm":"5px","marginBottomMd":"10px","marginBottomLg":"15px","marginBottomXl":"20px","marginBottomXxl":"25px","__typename":"UnstyledListItemThemeSettings"},"yiq":{"light":"#ffffff","dark":"#000000","__typename":"YiqThemeSettings"},"colorLightness":{"primaryDark":0.36,"primaryLight":0.74,"primaryLighter":0.89,"primaryLightest":0.95,"infoDark":0.39,"infoLight":0.72,"infoLighter":0.85,"infoLightest":0.93,"successDark":0.24,"successLight":0.62,"successLighter":0.8,"successLightest":0.91,"warningDark":0.39,"warningLight":0.68,"warningLighter":0.84,"warningLightest":0.93,"dangerDark":0.41,"dangerLight":0.72,"dangerLighter":0.89,"dangerLightest":0.95,"__typename":"ColorLightnessThemeSettings"},"localOverride":false,"__typename":"Theme"},"localOverride":false},"CachedAsset:text:en_US-components/common/EmailVerification-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/common/EmailVerification-1744658876102","value":{"email.verification.title":"Email Verification Required","email.verification.message.update.email":"To participate in the community, you must first verify your email address. The verification email was sent to {email}. To change your email, visit My Settings.","email.verification.message.resend.email":"To participate in the community, you must first verify your email address. The verification email was sent to {email}. Resend email."},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/common/Loading/LoadingDot-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/common/Loading/LoadingDot-1744658876102","value":{"title":"Loading..."},"localOverride":false},"CachedAsset:quilt:o365.prod:pages/blogs/BlogMessagePage:board:MicrosoftSentinelBlog-1744658874512":{"__typename":"CachedAsset","id":"quilt:o365.prod:pages/blogs/BlogMessagePage:board:MicrosoftSentinelBlog-1744658874512","value":{"id":"BlogMessagePage","container":{"id":"Common","headerProps":{"backgroundImageProps":null,"backgroundColor":null,"addComponents":null,"removeComponents":["community.widget.bannerWidget"],"componentOrder":null,"__typename":"QuiltContainerSectionProps"},"headerComponentProps":{"community.widget.breadcrumbWidget":{"disableLastCrumbForDesktop":false}},"footerProps":null,"footerComponentProps":null,"items":[{"id":"blog-article","layout":"ONE_COLUMN","bgColor":null,"showTitle":null,"showDescription":null,"textPosition":null,"textColor":null,"sectionEditLevel":"LOCKED","bgImage":null,"disableSpacing":null,"edgeToEdgeDisplay":null,"fullHeight":null,"showBorder":null,"__typename":"OneColumnQuiltSection","columnMap":{"main":[{"id":"blogs.widget.blogArticleWidget","className":"lia-blog-container","props":null,"__typename":"QuiltComponent"}],"__typename":"OneSectionColumns"}},{"id":"section-1729184836777","layout":"MAIN_SIDE","bgColor":"transparent","showTitle":false,"showDescription":false,"textPosition":"CENTER","textColor":"var(--lia-bs-body-color)","sectionEditLevel":null,"bgImage":null,"disableSpacing":null,"edgeToEdgeDisplay":null,"fullHeight":null,"showBorder":null,"__typename":"MainSideQuiltSection","columnMap":{"main":[],"side":[{"id":"custom.widget.Social_Sharing","className":null,"props":{"widgetVisibility":"signedInOrAnonymous","useTitle":true,"useBackground":true,"title":"Share","lazyLoad":false},"__typename":"QuiltComponent"}],"__typename":"MainSideSectionColumns"}}],"__typename":"QuiltContainer"},"__typename":"Quilt","localOverride":false},"localOverride":false},"CachedAsset:text:en_US-pages/blogs/BlogMessagePage-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-pages/blogs/BlogMessagePage-1744658876102","value":{"title":"{contextMessageSubject} | {communityTitle}","errorMissing":"This blog post cannot be found","name":"Blog Message Page","section.blog-article.title":"Blog Post","archivedMessageTitle":"This Content Has Been Archived","section.section-1729184836777.title":"","section.section-1729184836777.description":"","section.CncIde.title":"Blog Post","section.tifEmD.description":"","section.tifEmD.title":""},"localOverride":false},"CachedAsset:quiltWrapper:o365.prod:Common:1744410784155":{"__typename":"CachedAsset","id":"quiltWrapper:o365.prod:Common:1744410784155","value":{"id":"Common","header":{"backgroundImageProps":{"assetName":null,"backgroundSize":"COVER","backgroundRepeat":"NO_REPEAT","backgroundPosition":"CENTER_CENTER","lastModified":null,"__typename":"BackgroundImageProps"},"backgroundColor":"transparent","items":[{"id":"community.widget.navbarWidget","props":{"showUserName":true,"showRegisterLink":true,"useIconLanguagePicker":true,"useLabelLanguagePicker":true,"className":"QuiltComponent_lia-component-edit-mode__0nCcm","links":{"sideLinks":[],"mainLinks":[{"children":[],"linkType":"INTERNAL","id":"gxcuf89792","params":{},"routeName":"CommunityPage"},{"children":[],"linkType":"EXTERNAL","id":"external-link","url":"/Directory","target":"SELF"},{"children":[{"linkType":"INTERNAL","id":"microsoft365","params":{"categoryId":"microsoft365"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"microsoft-teams","params":{"categoryId":"MicrosoftTeams"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"windows","params":{"categoryId":"Windows"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"microsoft-securityand-compliance","params":{"categoryId":"microsoft-security"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"outlook","params":{"categoryId":"Outlook"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"planner","params":{"categoryId":"Planner"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"windows-server","params":{"categoryId":"Windows-Server"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"azure","params":{"categoryId":"Azure"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"exchange","params":{"categoryId":"Exchange"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"microsoft-endpoint-manager","params":{"categoryId":"microsoft-endpoint-manager"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"s-q-l-server","params":{"categoryId":"SQL-Server"},"routeName":"CategoryPage"},{"linkType":"EXTERNAL","id":"external-link-2","url":"/Directory","target":"SELF"}],"linkType":"EXTERNAL","id":"communities","url":"/","target":"BLANK"},{"children":[{"linkType":"INTERNAL","id":"education-sector","params":{"categoryId":"EducationSector"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"a-i","params":{"categoryId":"AI"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"i-t-ops-talk","params":{"categoryId":"ITOpsTalk"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"partner-community","params":{"categoryId":"PartnerCommunity"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"microsoft-mechanics","params":{"categoryId":"MicrosoftMechanics"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"healthcare-and-life-sciences","params":{"categoryId":"HealthcareAndLifeSciences"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"public-sector","params":{"categoryId":"PublicSector"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"io-t","params":{"categoryId":"IoT"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"driving-adoption","params":{"categoryId":"DrivingAdoption"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"s-m-b","params":{"categoryId":"SMB"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"startupsat-microsoft","params":{"categoryId":"StartupsatMicrosoft"},"routeName":"CategoryPage"},{"linkType":"EXTERNAL","id":"external-link-1","url":"/Directory","target":"SELF"}],"linkType":"EXTERNAL","id":"communities-1","url":"/","target":"SELF"},{"children":[],"linkType":"EXTERNAL","id":"external","url":"/Blogs","target":"SELF"},{"children":[],"linkType":"EXTERNAL","id":"external-1","url":"/Events","target":"SELF"},{"children":[{"linkType":"INTERNAL","id":"microsoft-learn-1","params":{"categoryId":"MicrosoftLearn"},"routeName":"CategoryPage"},{"linkType":"INTERNAL","id":"microsoft-learn-blog","params":{"boardId":"MicrosoftLearnBlog","categoryId":"MicrosoftLearn"},"routeName":"BlogBoardPage"},{"linkType":"EXTERNAL","id":"external-10","url":"https://learningroomdirectory.microsoft.com/","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-3","url":"https://docs.microsoft.com/learn/dynamics365/?WT.mc_id=techcom_header-webpage-m365","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-4","url":"https://docs.microsoft.com/learn/m365/?wt.mc_id=techcom_header-webpage-m365","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-5","url":"https://docs.microsoft.com/learn/topics/sci/?wt.mc_id=techcom_header-webpage-m365","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-6","url":"https://docs.microsoft.com/learn/powerplatform/?wt.mc_id=techcom_header-webpage-powerplatform","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-7","url":"https://docs.microsoft.com/learn/github/?wt.mc_id=techcom_header-webpage-github","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-8","url":"https://docs.microsoft.com/learn/teams/?wt.mc_id=techcom_header-webpage-teams","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-9","url":"https://docs.microsoft.com/learn/dotnet/?wt.mc_id=techcom_header-webpage-dotnet","target":"BLANK"},{"linkType":"EXTERNAL","id":"external-2","url":"https://docs.microsoft.com/learn/azure/?WT.mc_id=techcom_header-webpage-m365","target":"BLANK"}],"linkType":"INTERNAL","id":"microsoft-learn","params":{"categoryId":"MicrosoftLearn"},"routeName":"CategoryPage"},{"children":[],"linkType":"INTERNAL","id":"community-info-center","params":{"categoryId":"Community-Info-Center"},"routeName":"CategoryPage"}]},"style":{"boxShadow":"var(--lia-bs-box-shadow-sm)","controllerHighlightColor":"hsla(30, 100%, 50%)","linkFontWeight":"400","dropdownDividerMarginBottom":"10px","hamburgerBorderHover":"none","linkBoxShadowHover":"none","linkFontSize":"14px","backgroundOpacity":0.8,"controllerBorderRadius":"var(--lia-border-radius-50)","hamburgerBgColor":"transparent","hamburgerColor":"var(--lia-nav-controller-icon-color)","linkTextBorderBottom":"none","brandLogoHeight":"30px","linkBgHoverColor":"transparent","linkLetterSpacing":"normal","collapseMenuDividerOpacity":0.16,"dropdownPaddingBottom":"15px","paddingBottom":"15px","dropdownMenuOffset":"2px","hamburgerBgHoverColor":"transparent","borderBottom":"1px solid var(--lia-bs-border-color)","hamburgerBorder":"none","dropdownPaddingX":"10px","brandMarginRightSm":"10px","linkBoxShadow":"none","collapseMenuDividerBg":"var(--lia-nav-link-color)","linkColor":"var(--lia-bs-body-color)","linkJustifyContent":"flex-start","dropdownPaddingTop":"10px","controllerHighlightTextColor":"var(--lia-yiq-dark)","controllerTextColor":"var(--lia-nav-controller-icon-color)","background":{"imageAssetName":"","color":"var(--lia-bs-white)","size":"COVER","repeat":"NO_REPEAT","position":"CENTER_CENTER","imageLastModified":""},"linkBorderRadius":"var(--lia-bs-border-radius-sm)","linkHoverColor":"var(--lia-bs-body-color)","position":"FIXED","linkBorder":"none","linkTextBorderBottomHover":"2px solid var(--lia-bs-body-color)","brandMarginRight":"30px","hamburgerHoverColor":"var(--lia-nav-controller-icon-color)","linkBorderHover":"none","collapseMenuMarginLeft":"20px","linkFontStyle":"NORMAL","controllerTextHoverColor":"var(--lia-nav-controller-icon-hover-color)","linkPaddingX":"10px","linkPaddingY":"5px","paddingTop":"15px","linkTextTransform":"NONE","dropdownBorderColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.08)","controllerBgHoverColor":"hsla(var(--lia-bs-black-h), var(--lia-bs-black-s), var(--lia-bs-black-l), 0.1)","linkBgColor":"transparent","linkDropdownPaddingX":"var(--lia-nav-link-px)","linkDropdownPaddingY":"9px","controllerIconColor":"var(--lia-bs-body-color)","dropdownDividerMarginTop":"10px","linkGap":"10px","controllerIconHoverColor":"var(--lia-bs-body-color)"},"showSearchIcon":false,"languagePickerStyle":"iconAndLabel"},"__typename":"QuiltComponent"},{"id":"community.widget.breadcrumbWidget","props":{"backgroundColor":"transparent","linkHighlightColor":"var(--lia-bs-primary)","visualEffects":{"showBottomBorder":true},"linkTextColor":"var(--lia-bs-gray-700)"},"__typename":"QuiltComponent"},{"id":"custom.widget.community_banner","props":{"widgetVisibility":"signedInOrAnonymous","useTitle":true,"usePageWidth":false,"useBackground":false,"title":"","lazyLoad":false},"__typename":"QuiltComponent"},{"id":"custom.widget.HeroBanner","props":{"widgetVisibility":"signedInOrAnonymous","usePageWidth":false,"useTitle":true,"cMax_items":3,"useBackground":false,"title":"","lazyLoad":false,"widgetChooser":"custom.widget.HeroBanner"},"__typename":"QuiltComponent"}],"__typename":"QuiltWrapperSection"},"footer":{"backgroundImageProps":{"assetName":null,"backgroundSize":"COVER","backgroundRepeat":"NO_REPEAT","backgroundPosition":"CENTER_CENTER","lastModified":null,"__typename":"BackgroundImageProps"},"backgroundColor":"transparent","items":[{"id":"custom.widget.MicrosoftFooter","props":{"widgetVisibility":"signedInOrAnonymous","useTitle":true,"useBackground":false,"title":"","lazyLoad":false},"__typename":"QuiltComponent"}],"__typename":"QuiltWrapperSection"},"__typename":"QuiltWrapper","localOverride":false},"localOverride":false},"CachedAsset:text:en_US-components/common/ActionFeedback-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/common/ActionFeedback-1744658876102","value":{"joinedGroupHub.title":"Welcome","joinedGroupHub.message":"You are now a member of this group and are subscribed to updates.","groupHubInviteNotFound.title":"Invitation Not Found","groupHubInviteNotFound.message":"Sorry, we could not find your invitation to the group. The owner may have canceled the invite.","groupHubNotFound.title":"Group Not Found","groupHubNotFound.message":"The grouphub you tried to join does not exist. It may have been deleted.","existingGroupHubMember.title":"Already Joined","existingGroupHubMember.message":"You are already a member of this group.","accountLocked.title":"Account Locked","accountLocked.message":"Your account has been locked due to multiple failed attempts. Try again in {lockoutTime} minutes.","editedGroupHub.title":"Changes Saved","editedGroupHub.message":"Your group has been updated.","leftGroupHub.title":"Goodbye","leftGroupHub.message":"You are no longer a member of this group and will not receive future updates.","deletedGroupHub.title":"Deleted","deletedGroupHub.message":"The group has been deleted.","groupHubCreated.title":"Group Created","groupHubCreated.message":"{groupHubName} is ready to use","accountClosed.title":"Account Closed","accountClosed.message":"The account has been closed and you will now be redirected to the homepage","resetTokenExpired.title":"Reset Password Link has Expired","resetTokenExpired.message":"Try resetting your password again","invalidUrl.title":"Invalid URL","invalidUrl.message":"The URL you're using is not recognized. Verify your URL and try again.","accountClosedForUser.title":"Account Closed","accountClosedForUser.message":"{userName}'s account is closed","inviteTokenInvalid.title":"Invitation Invalid","inviteTokenInvalid.message":"Your invitation to the community has been canceled or expired.","inviteTokenError.title":"Invitation Verification Failed","inviteTokenError.message":"The url you are utilizing is not recognized. Verify your URL and try again","pageNotFound.title":"Access Denied","pageNotFound.message":"You do not have access to this area of the community or it doesn't exist","eventAttending.title":"Responded as Attending","eventAttending.message":"You'll be notified when there's new activity and reminded as the event approaches","eventInterested.title":"Responded as Interested","eventInterested.message":"You'll be notified when there's new activity and reminded as the event approaches","eventNotFound.title":"Event Not Found","eventNotFound.message":"The event you tried to respond to does not exist.","redirectToRelatedPage.title":"Showing Related Content","redirectToRelatedPageForBaseUsers.title":"Showing Related Content","redirectToRelatedPageForBaseUsers.message":"The content you are trying to access is archived","redirectToRelatedPage.message":"The content you are trying to access is archived","relatedUrl.archivalLink.flyoutMessage":"The content you are trying to access is archived View Archived Content"},"localOverride":false},"CachedAsset:component:custom.widget.community_banner-en-1744400827793":{"__typename":"CachedAsset","id":"component:custom.widget.community_banner-en-1744400827793","value":{"component":{"id":"custom.widget.community_banner","template":{"id":"community_banner","markupLanguage":"HANDLEBARS","style":".community-banner {\n a.top-bar.btn {\n top: 0px;\n width: 100%;\n z-index: 999;\n text-align: center;\n left: 0px;\n background: #0068b8;\n color: white;\n padding: 10px 0px;\n display: block;\n box-shadow: none !important;\n border: none !important;\n border-radius: none !important;\n margin: 0px !important;\n font-size: 14px;\n }\n}\n","texts":null,"defaults":{"config":{"applicablePages":[],"description":"community announcement text","fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[],"__typename":"ComponentProperties"},"components":[{"id":"custom.widget.community_banner","form":null,"config":null,"props":[],"__typename":"Component"}],"grouping":"CUSTOM","__typename":"ComponentTemplate"},"properties":{"config":{"applicablePages":[],"description":"community announcement text","fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[],"__typename":"ComponentProperties"},"form":null,"__typename":"Component","localOverride":false},"globalCss":{"css":".custom_widget_community_banner_community-banner_1x9u2_1 {\n a.custom_widget_community_banner_top-bar_1x9u2_2.custom_widget_community_banner_btn_1x9u2_2 {\n top: 0;\n width: 100%;\n z-index: 999;\n text-align: center;\n left: 0;\n background: #0068b8;\n color: white;\n padding: 0.625rem 0;\n display: block;\n box-shadow: none !important;\n border: none !important;\n border-radius: none !important;\n margin: 0 !important;\n font-size: 0.875rem;\n }\n}\n","tokens":{"community-banner":"custom_widget_community_banner_community-banner_1x9u2_1","top-bar":"custom_widget_community_banner_top-bar_1x9u2_2","btn":"custom_widget_community_banner_btn_1x9u2_2"}},"form":null},"localOverride":false},"CachedAsset:component:custom.widget.HeroBanner-en-1744400827793":{"__typename":"CachedAsset","id":"component:custom.widget.HeroBanner-en-1744400827793","value":{"component":{"id":"custom.widget.HeroBanner","template":{"id":"HeroBanner","markupLanguage":"REACT","style":null,"texts":{"searchPlaceholderText":"Search this community","followActionText":"Follow","unfollowActionText":"Following","searchOnHoverText":"Please enter your search term(s) and then press return key to complete a search.","blogs.sidebar.pagetitle":"Latest Blogs | Microsoft Tech Community","followThisNode":"Follow this node","unfollowThisNode":"Unfollow this node"},"defaults":{"config":{"applicablePages":[],"description":null,"fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[{"id":"max_items","dataType":"NUMBER","list":false,"defaultValue":"3","label":"Max Items","description":"The maximum number of items to display in the carousel","possibleValues":null,"control":"INPUT","__typename":"PropDefinition"}],"__typename":"ComponentProperties"},"components":[{"id":"custom.widget.HeroBanner","form":{"fields":[{"id":"widgetChooser","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"title","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"useTitle","validation":null,"noValidation":null,"dataType":"BOOLEAN","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"useBackground","validation":null,"noValidation":null,"dataType":"BOOLEAN","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"widgetVisibility","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"moreOptions","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"cMax_items","validation":null,"noValidation":null,"dataType":"NUMBER","list":false,"control":"INPUT","defaultValue":"3","label":"Max Items","description":"The maximum number of items to display in the carousel","possibleValues":null,"__typename":"FormField"}],"layout":{"rows":[{"id":"widgetChooserGroup","type":"fieldset","as":null,"items":[{"id":"widgetChooser","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"titleGroup","type":"fieldset","as":null,"items":[{"id":"title","className":null,"__typename":"FormFieldRef"},{"id":"useTitle","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"useBackground","type":"fieldset","as":null,"items":[{"id":"useBackground","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"widgetVisibility","type":"fieldset","as":null,"items":[{"id":"widgetVisibility","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"moreOptionsGroup","type":"fieldset","as":null,"items":[{"id":"moreOptions","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"componentPropsGroup","type":"fieldset","as":null,"items":[{"id":"cMax_items","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"}],"actionButtons":null,"className":"custom_widget_HeroBanner_form","formGroupFieldSeparator":"divider","__typename":"FormLayout"},"__typename":"Form"},"config":null,"props":[],"__typename":"Component"}],"grouping":"CUSTOM","__typename":"ComponentTemplate"},"properties":{"config":{"applicablePages":[],"description":null,"fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[{"id":"max_items","dataType":"NUMBER","list":false,"defaultValue":"3","label":"Max Items","description":"The maximum number of items to display in the carousel","possibleValues":null,"control":"INPUT","__typename":"PropDefinition"}],"__typename":"ComponentProperties"},"form":{"fields":[{"id":"widgetChooser","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"title","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"useTitle","validation":null,"noValidation":null,"dataType":"BOOLEAN","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"useBackground","validation":null,"noValidation":null,"dataType":"BOOLEAN","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"widgetVisibility","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"moreOptions","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"cMax_items","validation":null,"noValidation":null,"dataType":"NUMBER","list":false,"control":"INPUT","defaultValue":"3","label":"Max Items","description":"The maximum number of items to display in the carousel","possibleValues":null,"__typename":"FormField"}],"layout":{"rows":[{"id":"widgetChooserGroup","type":"fieldset","as":null,"items":[{"id":"widgetChooser","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"titleGroup","type":"fieldset","as":null,"items":[{"id":"title","className":null,"__typename":"FormFieldRef"},{"id":"useTitle","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"useBackground","type":"fieldset","as":null,"items":[{"id":"useBackground","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"widgetVisibility","type":"fieldset","as":null,"items":[{"id":"widgetVisibility","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"moreOptionsGroup","type":"fieldset","as":null,"items":[{"id":"moreOptions","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"componentPropsGroup","type":"fieldset","as":null,"items":[{"id":"cMax_items","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"}],"actionButtons":null,"className":"custom_widget_HeroBanner_form","formGroupFieldSeparator":"divider","__typename":"FormLayout"},"__typename":"Form"},"__typename":"Component","localOverride":false},"globalCss":null,"form":{"fields":[{"id":"widgetChooser","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"title","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"useTitle","validation":null,"noValidation":null,"dataType":"BOOLEAN","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"useBackground","validation":null,"noValidation":null,"dataType":"BOOLEAN","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"widgetVisibility","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"moreOptions","validation":null,"noValidation":null,"dataType":"STRING","list":null,"control":null,"defaultValue":null,"label":null,"description":null,"possibleValues":null,"__typename":"FormField"},{"id":"cMax_items","validation":null,"noValidation":null,"dataType":"NUMBER","list":false,"control":"INPUT","defaultValue":"3","label":"Max Items","description":"The maximum number of items to display in the carousel","possibleValues":null,"__typename":"FormField"}],"layout":{"rows":[{"id":"widgetChooserGroup","type":"fieldset","as":null,"items":[{"id":"widgetChooser","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"titleGroup","type":"fieldset","as":null,"items":[{"id":"title","className":null,"__typename":"FormFieldRef"},{"id":"useTitle","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"useBackground","type":"fieldset","as":null,"items":[{"id":"useBackground","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"widgetVisibility","type":"fieldset","as":null,"items":[{"id":"widgetVisibility","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"moreOptionsGroup","type":"fieldset","as":null,"items":[{"id":"moreOptions","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"},{"id":"componentPropsGroup","type":"fieldset","as":null,"items":[{"id":"cMax_items","className":null,"__typename":"FormFieldRef"}],"props":null,"legend":null,"description":null,"className":null,"viewVariant":null,"toggleState":null,"__typename":"FormFieldset"}],"actionButtons":null,"className":"custom_widget_HeroBanner_form","formGroupFieldSeparator":"divider","__typename":"FormLayout"},"__typename":"Form"}},"localOverride":false},"CachedAsset:component:custom.widget.Social_Sharing-en-1744400827793":{"__typename":"CachedAsset","id":"component:custom.widget.Social_Sharing-en-1744400827793","value":{"component":{"id":"custom.widget.Social_Sharing","template":{"id":"Social_Sharing","markupLanguage":"HANDLEBARS","style":".social-share {\n .sharing-options {\n position: relative;\n margin: 0;\n padding: 0;\n line-height: 10px;\n display: flex;\n justify-content: left;\n gap: 5px;\n list-style-type: none;\n li {\n text-align: left;\n a {\n min-width: 30px;\n min-height: 30px;\n display: block;\n padding: 1px;\n .social-share-linkedin {\n img {\n background-color: rgb(0, 119, 181);\n }\n }\n .social-share-facebook {\n img {\n background-color: rgb(59, 89, 152);\n }\n }\n .social-share-x {\n img {\n background-color: rgb(0, 0, 0);\n }\n }\n .social-share-rss {\n img {\n background-color: rgb(0, 0, 0);\n }\n }\n .social-share-reddit {\n img {\n background-color: rgb(255, 69, 0);\n }\n }\n .social-share-email {\n img {\n background-color: rgb(132, 132, 132);\n }\n }\n }\n a {\n img {\n height: 2rem;\n }\n }\n }\n }\n}\n","texts":null,"defaults":{"config":{"applicablePages":[],"description":"Adds buttons to share to various social media websites","fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[],"__typename":"ComponentProperties"},"components":[{"id":"custom.widget.Social_Sharing","form":null,"config":null,"props":[],"__typename":"Component"}],"grouping":"CUSTOM","__typename":"ComponentTemplate"},"properties":{"config":{"applicablePages":[],"description":"Adds buttons to share to various social media websites","fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[],"__typename":"ComponentProperties"},"form":null,"__typename":"Component","localOverride":false},"globalCss":{"css":".custom_widget_Social_Sharing_social-share_c7xxz_1 {\n .custom_widget_Social_Sharing_sharing-options_c7xxz_2 {\n position: relative;\n margin: 0;\n padding: 0;\n line-height: 0.625rem;\n display: flex;\n justify-content: left;\n gap: 0.3125rem;\n list-style-type: none;\n li {\n text-align: left;\n a {\n min-width: 1.875rem;\n min-height: 1.875rem;\n display: block;\n padding: 0.0625rem;\n .custom_widget_Social_Sharing_social-share-linkedin_c7xxz_18 {\n img {\n background-color: rgb(0, 119, 181);\n }\n }\n .custom_widget_Social_Sharing_social-share-facebook_c7xxz_23 {\n img {\n background-color: rgb(59, 89, 152);\n }\n }\n .custom_widget_Social_Sharing_social-share-x_c7xxz_28 {\n img {\n background-color: rgb(0, 0, 0);\n }\n }\n .custom_widget_Social_Sharing_social-share-rss_c7xxz_33 {\n img {\n background-color: rgb(0, 0, 0);\n }\n }\n .custom_widget_Social_Sharing_social-share-reddit_c7xxz_38 {\n img {\n background-color: rgb(255, 69, 0);\n }\n }\n .custom_widget_Social_Sharing_social-share-email_c7xxz_43 {\n img {\n background-color: rgb(132, 132, 132);\n }\n }\n }\n a {\n img {\n height: 2rem;\n }\n }\n }\n }\n}\n","tokens":{"social-share":"custom_widget_Social_Sharing_social-share_c7xxz_1","sharing-options":"custom_widget_Social_Sharing_sharing-options_c7xxz_2","social-share-linkedin":"custom_widget_Social_Sharing_social-share-linkedin_c7xxz_18","social-share-facebook":"custom_widget_Social_Sharing_social-share-facebook_c7xxz_23","social-share-x":"custom_widget_Social_Sharing_social-share-x_c7xxz_28","social-share-rss":"custom_widget_Social_Sharing_social-share-rss_c7xxz_33","social-share-reddit":"custom_widget_Social_Sharing_social-share-reddit_c7xxz_38","social-share-email":"custom_widget_Social_Sharing_social-share-email_c7xxz_43"}},"form":null},"localOverride":false},"CachedAsset:component:custom.widget.MicrosoftFooter-en-1744400827793":{"__typename":"CachedAsset","id":"component:custom.widget.MicrosoftFooter-en-1744400827793","value":{"component":{"id":"custom.widget.MicrosoftFooter","template":{"id":"MicrosoftFooter","markupLanguage":"HANDLEBARS","style":".context-uhf {\n min-width: 280px;\n font-size: 15px;\n box-sizing: border-box;\n -ms-text-size-adjust: 100%;\n -webkit-text-size-adjust: 100%;\n & *,\n & *:before,\n & *:after {\n box-sizing: inherit;\n }\n a.c-uhff-link {\n color: #616161;\n word-break: break-word;\n text-decoration: none;\n }\n &a:link,\n &a:focus,\n &a:hover,\n &a:active,\n &a:visited {\n text-decoration: none;\n color: inherit;\n }\n & div {\n font-family: 'Segoe UI', SegoeUI, 'Helvetica Neue', Helvetica, Arial, sans-serif;\n }\n}\n.c-uhff {\n background: #f2f2f2;\n margin: -1.5625;\n width: auto;\n height: auto;\n}\n.c-uhff-nav {\n margin: 0 auto;\n max-width: calc(1600px + 10%);\n padding: 0 5%;\n box-sizing: inherit;\n &:before,\n &:after {\n content: ' ';\n display: table;\n clear: left;\n }\n @media only screen and (max-width: 1083px) {\n padding-left: 12px;\n }\n .c-heading-4 {\n color: #616161;\n word-break: break-word;\n font-size: 15px;\n line-height: 20px;\n padding: 36px 0 4px;\n font-weight: 600;\n }\n .c-uhff-nav-row {\n .c-uhff-nav-group {\n display: block;\n float: left;\n min-height: 1px;\n vertical-align: text-top;\n padding: 0 12px;\n width: 100%;\n zoom: 1;\n &:first-child {\n padding-left: 0;\n @media only screen and (max-width: 1083px) {\n padding-left: 12px;\n }\n }\n @media only screen and (min-width: 540px) and (max-width: 1082px) {\n width: 33.33333%;\n }\n @media only screen and (min-width: 1083px) {\n width: 16.6666666667%;\n }\n ul.c-list.f-bare {\n font-size: 11px;\n line-height: 16px;\n margin-top: 0;\n margin-bottom: 0;\n padding-left: 0;\n list-style-type: none;\n li {\n word-break: break-word;\n padding: 8px 0;\n margin: 0;\n }\n }\n }\n }\n}\n.c-uhff-base {\n background: #f2f2f2;\n margin: 0 auto;\n max-width: calc(1600px + 10%);\n padding: 30px 5% 16px;\n &:before,\n &:after {\n content: ' ';\n display: table;\n }\n &:after {\n clear: both;\n }\n a.c-uhff-ccpa {\n font-size: 11px;\n line-height: 16px;\n float: left;\n margin: 3px 0;\n }\n a.c-uhff-ccpa:hover {\n text-decoration: underline;\n }\n ul.c-list {\n font-size: 11px;\n line-height: 16px;\n float: right;\n margin: 3px 0;\n color: #616161;\n li {\n padding: 0 24px 4px 0;\n display: inline-block;\n }\n }\n .c-list.f-bare {\n padding-left: 0;\n list-style-type: none;\n }\n @media only screen and (max-width: 1083px) {\n display: flex;\n flex-wrap: wrap;\n padding: 30px 24px 16px;\n }\n}\n\n.social-share {\n position: fixed;\n top: 60%;\n transform: translateY(-50%);\n left: 0;\n z-index: 1000;\n}\n\n.sharing-options {\n list-style: none;\n padding: 0;\n margin: 0;\n display: block;\n flex-direction: column;\n background-color: white;\n width: 43px;\n border-radius: 0px 7px 7px 0px;\n}\n.linkedin-icon {\n border-top-right-radius: 7px;\n}\n.linkedin-icon:hover {\n border-radius: 0;\n}\n.social-share-rss-image {\n border-bottom-right-radius: 7px;\n}\n.social-share-rss-image:hover {\n border-radius: 0;\n}\n\n.social-link-footer {\n position: relative;\n display: block;\n margin: -2px 0;\n transition: all 0.2s ease;\n}\n.social-link-footer:hover .linkedin-icon {\n border-radius: 0;\n}\n.social-link-footer:hover .social-share-rss-image {\n border-radius: 0;\n}\n\n.social-link-footer img {\n width: 40px;\n height: auto;\n transition: filter 0.3s ease;\n}\n\n.social-share-list {\n width: 40px;\n}\n.social-share-rss-image {\n width: 40px;\n}\n\n.share-icon {\n border: 2px solid transparent;\n display: inline-block;\n position: relative;\n}\n\n.share-icon:hover {\n opacity: 1;\n border: 2px solid white;\n box-sizing: border-box;\n}\n\n.share-icon:hover .label {\n opacity: 1;\n visibility: visible;\n border: 2px solid white;\n box-sizing: border-box;\n border-left: none;\n}\n\n.label {\n position: absolute;\n left: 100%;\n white-space: nowrap;\n opacity: 0;\n visibility: hidden;\n transition: all 0.2s ease;\n color: white;\n border-radius: 0 10 0 10px;\n top: 50%;\n transform: translateY(-50%);\n height: 40px;\n border-radius: 0 6px 6px 0;\n display: flex;\n align-items: center;\n justify-content: center;\n padding: 20px 5px 20px 8px;\n margin-left: -1px;\n}\n.linkedin {\n background-color: #0474b4;\n}\n.facebook {\n background-color: #3c5c9c;\n}\n.twitter {\n background-color: white;\n color: black;\n}\n.reddit {\n background-color: #fc4404;\n}\n.mail {\n background-color: #848484;\n}\n.bluesky {\n background-color: white;\n color: black;\n}\n.rss {\n background-color: #ec7b1c;\n}\n#RSS {\n width: 40px;\n height: 40px;\n}\n\n@media (max-width: 991px) {\n .social-share {\n display: none;\n }\n}\n","texts":{"New tab":"What's New","New 1":"Surface Laptop Studio 2","New 2":"Surface Laptop Go 3","New 3":"Surface Pro 9","New 4":"Surface Laptop 5","New 5":"Surface Studio 2+","New 6":"Copilot in Windows","New 7":"Microsoft 365","New 8":"Windows 11 apps","Store tab":"Microsoft Store","Store 1":"Account Profile","Store 2":"Download Center","Store 3":"Microsoft Store Support","Store 4":"Returns","Store 5":"Order tracking","Store 6":"Certified Refurbished","Store 7":"Microsoft Store Promise","Store 8":"Flexible Payments","Education tab":"Education","Edu 1":"Microsoft in education","Edu 2":"Devices for education","Edu 3":"Microsoft Teams for Education","Edu 4":"Microsoft 365 Education","Edu 5":"How to buy for your school","Edu 6":"Educator Training and development","Edu 7":"Deals for students and parents","Edu 8":"Azure for students","Business tab":"Business","Bus 1":"Microsoft Cloud","Bus 2":"Microsoft Security","Bus 3":"Dynamics 365","Bus 4":"Microsoft 365","Bus 5":"Microsoft Power Platform","Bus 6":"Microsoft Teams","Bus 7":"Microsoft Industry","Bus 8":"Small Business","Developer tab":"Developer & IT","Dev 1":"Azure","Dev 2":"Developer Center","Dev 3":"Documentation","Dev 4":"Microsoft Learn","Dev 5":"Microsoft Tech Community","Dev 6":"Azure Marketplace","Dev 7":"AppSource","Dev 8":"Visual Studio","Company tab":"Company","Com 1":"Careers","Com 2":"About Microsoft","Com 3":"Company News","Com 4":"Privacy at Microsoft","Com 5":"Investors","Com 6":"Diversity and inclusion","Com 7":"Accessiblity","Com 8":"Sustainibility"},"defaults":{"config":{"applicablePages":[],"description":"The Microsoft Footer","fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[],"__typename":"ComponentProperties"},"components":[{"id":"custom.widget.MicrosoftFooter","form":null,"config":null,"props":[],"__typename":"Component"}],"grouping":"CUSTOM","__typename":"ComponentTemplate"},"properties":{"config":{"applicablePages":[],"description":"The Microsoft Footer","fetchedContent":null,"__typename":"ComponentConfiguration"},"props":[],"__typename":"ComponentProperties"},"form":null,"__typename":"Component","localOverride":false},"globalCss":{"css":".custom_widget_MicrosoftFooter_context-uhf_105bp_1 {\n min-width: 17.5rem;\n font-size: 0.9375rem;\n box-sizing: border-box;\n -ms-text-size-adjust: 100%;\n -webkit-text-size-adjust: 100%;\n & *,\n & *:before,\n & *:after {\n box-sizing: inherit;\n }\n a.custom_widget_MicrosoftFooter_c-uhff-link_105bp_12 {\n color: #616161;\n word-break: break-word;\n text-decoration: none;\n }\n &a:link,\n &a:focus,\n &a:hover,\n &a:active,\n &a:visited {\n text-decoration: none;\n color: inherit;\n }\n & div {\n font-family: 'Segoe UI', SegoeUI, 'Helvetica Neue', Helvetica, Arial, sans-serif;\n }\n}\n.custom_widget_MicrosoftFooter_c-uhff_105bp_12 {\n background: #f2f2f2;\n margin: -1.5625;\n width: auto;\n height: auto;\n}\n.custom_widget_MicrosoftFooter_c-uhff-nav_105bp_35 {\n margin: 0 auto;\n max-width: calc(100rem + 10%);\n padding: 0 5%;\n box-sizing: inherit;\n &:before,\n &:after {\n content: ' ';\n display: table;\n clear: left;\n }\n @media only screen and (max-width: 1083px) {\n padding-left: 0.75rem;\n }\n .custom_widget_MicrosoftFooter_c-heading-4_105bp_49 {\n color: #616161;\n word-break: break-word;\n font-size: 0.9375rem;\n line-height: 1.25rem;\n padding: 2.25rem 0 0.25rem;\n font-weight: 600;\n }\n .custom_widget_MicrosoftFooter_c-uhff-nav-row_105bp_57 {\n .custom_widget_MicrosoftFooter_c-uhff-nav-group_105bp_58 {\n display: block;\n float: left;\n min-height: 0.0625rem;\n vertical-align: text-top;\n padding: 0 0.75rem;\n width: 100%;\n zoom: 1;\n &:first-child {\n padding-left: 0;\n @media only screen and (max-width: 1083px) {\n padding-left: 0.75rem;\n }\n }\n @media only screen and (min-width: 540px) and (max-width: 1082px) {\n width: 33.33333%;\n }\n @media only screen and (min-width: 1083px) {\n width: 16.6666666667%;\n }\n ul.custom_widget_MicrosoftFooter_c-list_105bp_78.custom_widget_MicrosoftFooter_f-bare_105bp_78 {\n font-size: 0.6875rem;\n line-height: 1rem;\n margin-top: 0;\n margin-bottom: 0;\n padding-left: 0;\n list-style-type: none;\n li {\n word-break: break-word;\n padding: 0.5rem 0;\n margin: 0;\n }\n }\n }\n }\n}\n.custom_widget_MicrosoftFooter_c-uhff-base_105bp_94 {\n background: #f2f2f2;\n margin: 0 auto;\n max-width: calc(100rem + 10%);\n padding: 1.875rem 5% 1rem;\n &:before,\n &:after {\n content: ' ';\n display: table;\n }\n &:after {\n clear: both;\n }\n a.custom_widget_MicrosoftFooter_c-uhff-ccpa_105bp_107 {\n font-size: 0.6875rem;\n line-height: 1rem;\n float: left;\n margin: 0.1875rem 0;\n }\n a.custom_widget_MicrosoftFooter_c-uhff-ccpa_105bp_107:hover {\n text-decoration: underline;\n }\n ul.custom_widget_MicrosoftFooter_c-list_105bp_78 {\n font-size: 0.6875rem;\n line-height: 1rem;\n float: right;\n margin: 0.1875rem 0;\n color: #616161;\n li {\n padding: 0 1.5rem 0.25rem 0;\n display: inline-block;\n }\n }\n .custom_widget_MicrosoftFooter_c-list_105bp_78.custom_widget_MicrosoftFooter_f-bare_105bp_78 {\n padding-left: 0;\n list-style-type: none;\n }\n @media only screen and (max-width: 1083px) {\n display: flex;\n flex-wrap: wrap;\n padding: 1.875rem 1.5rem 1rem;\n }\n}\n.custom_widget_MicrosoftFooter_social-share_105bp_138 {\n position: fixed;\n top: 60%;\n transform: translateY(-50%);\n left: 0;\n z-index: 1000;\n}\n.custom_widget_MicrosoftFooter_sharing-options_105bp_146 {\n list-style: none;\n padding: 0;\n margin: 0;\n display: block;\n flex-direction: column;\n background-color: white;\n width: 2.6875rem;\n border-radius: 0 0.4375rem 0.4375rem 0;\n}\n.custom_widget_MicrosoftFooter_linkedin-icon_105bp_156 {\n border-top-right-radius: 7px;\n}\n.custom_widget_MicrosoftFooter_linkedin-icon_105bp_156:hover {\n border-radius: 0;\n}\n.custom_widget_MicrosoftFooter_social-share-rss-image_105bp_162 {\n border-bottom-right-radius: 7px;\n}\n.custom_widget_MicrosoftFooter_social-share-rss-image_105bp_162:hover {\n border-radius: 0;\n}\n.custom_widget_MicrosoftFooter_social-link-footer_105bp_169 {\n position: relative;\n display: block;\n margin: -0.125rem 0;\n transition: all 0.2s ease;\n}\n.custom_widget_MicrosoftFooter_social-link-footer_105bp_169:hover .custom_widget_MicrosoftFooter_linkedin-icon_105bp_156 {\n border-radius: 0;\n}\n.custom_widget_MicrosoftFooter_social-link-footer_105bp_169:hover .custom_widget_MicrosoftFooter_social-share-rss-image_105bp_162 {\n border-radius: 0;\n}\n.custom_widget_MicrosoftFooter_social-link-footer_105bp_169 img {\n width: 2.5rem;\n height: auto;\n transition: filter 0.3s ease;\n}\n.custom_widget_MicrosoftFooter_social-share-list_105bp_188 {\n width: 2.5rem;\n}\n.custom_widget_MicrosoftFooter_social-share-rss-image_105bp_162 {\n width: 2.5rem;\n}\n.custom_widget_MicrosoftFooter_share-icon_105bp_195 {\n border: 2px solid transparent;\n display: inline-block;\n position: relative;\n}\n.custom_widget_MicrosoftFooter_share-icon_105bp_195:hover {\n opacity: 1;\n border: 2px solid white;\n box-sizing: border-box;\n}\n.custom_widget_MicrosoftFooter_share-icon_105bp_195:hover .custom_widget_MicrosoftFooter_label_105bp_207 {\n opacity: 1;\n visibility: visible;\n border: 2px solid white;\n box-sizing: border-box;\n border-left: none;\n}\n.custom_widget_MicrosoftFooter_label_105bp_207 {\n position: absolute;\n left: 100%;\n white-space: nowrap;\n opacity: 0;\n visibility: hidden;\n transition: all 0.2s ease;\n color: white;\n border-radius: 0 10 0 0.625rem;\n top: 50%;\n transform: translateY(-50%);\n height: 2.5rem;\n border-radius: 0 0.375rem 0.375rem 0;\n display: flex;\n align-items: center;\n justify-content: center;\n padding: 1.25rem 0.3125rem 1.25rem 0.5rem;\n margin-left: -0.0625rem;\n}\n.custom_widget_MicrosoftFooter_linkedin_105bp_156 {\n background-color: #0474b4;\n}\n.custom_widget_MicrosoftFooter_facebook_105bp_237 {\n background-color: #3c5c9c;\n}\n.custom_widget_MicrosoftFooter_twitter_105bp_240 {\n background-color: white;\n color: black;\n}\n.custom_widget_MicrosoftFooter_reddit_105bp_244 {\n background-color: #fc4404;\n}\n.custom_widget_MicrosoftFooter_mail_105bp_247 {\n background-color: #848484;\n}\n.custom_widget_MicrosoftFooter_bluesky_105bp_250 {\n background-color: white;\n color: black;\n}\n.custom_widget_MicrosoftFooter_rss_105bp_254 {\n background-color: #ec7b1c;\n}\n#custom_widget_MicrosoftFooter_RSS_105bp_1 {\n width: 2.5rem;\n height: 2.5rem;\n}\n@media (max-width: 991px) {\n .custom_widget_MicrosoftFooter_social-share_105bp_138 {\n display: none;\n }\n}\n","tokens":{"context-uhf":"custom_widget_MicrosoftFooter_context-uhf_105bp_1","c-uhff-link":"custom_widget_MicrosoftFooter_c-uhff-link_105bp_12","c-uhff":"custom_widget_MicrosoftFooter_c-uhff_105bp_12","c-uhff-nav":"custom_widget_MicrosoftFooter_c-uhff-nav_105bp_35","c-heading-4":"custom_widget_MicrosoftFooter_c-heading-4_105bp_49","c-uhff-nav-row":"custom_widget_MicrosoftFooter_c-uhff-nav-row_105bp_57","c-uhff-nav-group":"custom_widget_MicrosoftFooter_c-uhff-nav-group_105bp_58","c-list":"custom_widget_MicrosoftFooter_c-list_105bp_78","f-bare":"custom_widget_MicrosoftFooter_f-bare_105bp_78","c-uhff-base":"custom_widget_MicrosoftFooter_c-uhff-base_105bp_94","c-uhff-ccpa":"custom_widget_MicrosoftFooter_c-uhff-ccpa_105bp_107","social-share":"custom_widget_MicrosoftFooter_social-share_105bp_138","sharing-options":"custom_widget_MicrosoftFooter_sharing-options_105bp_146","linkedin-icon":"custom_widget_MicrosoftFooter_linkedin-icon_105bp_156","social-share-rss-image":"custom_widget_MicrosoftFooter_social-share-rss-image_105bp_162","social-link-footer":"custom_widget_MicrosoftFooter_social-link-footer_105bp_169","social-share-list":"custom_widget_MicrosoftFooter_social-share-list_105bp_188","share-icon":"custom_widget_MicrosoftFooter_share-icon_105bp_195","label":"custom_widget_MicrosoftFooter_label_105bp_207","linkedin":"custom_widget_MicrosoftFooter_linkedin_105bp_156","facebook":"custom_widget_MicrosoftFooter_facebook_105bp_237","twitter":"custom_widget_MicrosoftFooter_twitter_105bp_240","reddit":"custom_widget_MicrosoftFooter_reddit_105bp_244","mail":"custom_widget_MicrosoftFooter_mail_105bp_247","bluesky":"custom_widget_MicrosoftFooter_bluesky_105bp_250","rss":"custom_widget_MicrosoftFooter_rss_105bp_254","RSS":"custom_widget_MicrosoftFooter_RSS_105bp_1"}},"form":null},"localOverride":false},"CachedAsset:text:en_US-components/community/Breadcrumb-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/community/Breadcrumb-1744658876102","value":{"navLabel":"Breadcrumbs","dropdown":"Additional parent page navigation"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageBanner-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageBanner-1744658876102","value":{"messageMarkedAsSpam":"This post has been marked as spam","messageMarkedAsSpam@board:TKB":"This article has been marked as spam","messageMarkedAsSpam@board:BLOG":"This post has been marked as spam","messageMarkedAsSpam@board:FORUM":"This discussion has been marked as spam","messageMarkedAsSpam@board:OCCASION":"This event has been marked as spam","messageMarkedAsSpam@board:IDEA":"This idea has been marked as spam","manageSpam":"Manage Spam","messageMarkedAsAbuse":"This post has been marked as abuse","messageMarkedAsAbuse@board:TKB":"This article has been marked as abuse","messageMarkedAsAbuse@board:BLOG":"This post has been marked as abuse","messageMarkedAsAbuse@board:FORUM":"This discussion has been marked as abuse","messageMarkedAsAbuse@board:OCCASION":"This event has been marked as abuse","messageMarkedAsAbuse@board:IDEA":"This idea has been marked as abuse","preModCommentAuthorText":"This comment will be published as soon as it is approved","preModCommentModeratorText":"This comment is awaiting moderation","messageMarkedAsOther":"This post has been rejected due to other reasons","messageMarkedAsOther@board:TKB":"This article has been rejected due to other reasons","messageMarkedAsOther@board:BLOG":"This post has been rejected due to other reasons","messageMarkedAsOther@board:FORUM":"This discussion has been rejected due to other reasons","messageMarkedAsOther@board:OCCASION":"This event has been rejected due to other reasons","messageMarkedAsOther@board:IDEA":"This idea has been rejected due to other reasons","messageArchived":"This post was archived on {date}","relatedUrl":"View Related Content","relatedContentText":"Showing related content","archivedContentLink":"View Archived Content"},"localOverride":false},"Category:category:Exchange":{"__typename":"Category","id":"category:Exchange","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:Planner":{"__typename":"Category","id":"category:Planner","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:Outlook":{"__typename":"Category","id":"category:Outlook","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:Community-Info-Center":{"__typename":"Category","id":"category:Community-Info-Center","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:EducationSector":{"__typename":"Category","id":"category:EducationSector","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:DrivingAdoption":{"__typename":"Category","id":"category:DrivingAdoption","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:Azure":{"__typename":"Category","id":"category:Azure","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:Windows-Server":{"__typename":"Category","id":"category:Windows-Server","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:SQL-Server":{"__typename":"Category","id":"category:SQL-Server","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:MicrosoftTeams":{"__typename":"Category","id":"category:MicrosoftTeams","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:PublicSector":{"__typename":"Category","id":"category:PublicSector","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:microsoft365":{"__typename":"Category","id":"category:microsoft365","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:IoT":{"__typename":"Category","id":"category:IoT","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:HealthcareAndLifeSciences":{"__typename":"Category","id":"category:HealthcareAndLifeSciences","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:SMB":{"__typename":"Category","id":"category:SMB","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:ITOpsTalk":{"__typename":"Category","id":"category:ITOpsTalk","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:microsoft-endpoint-manager":{"__typename":"Category","id":"category:microsoft-endpoint-manager","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:MicrosoftLearn":{"__typename":"Category","id":"category:MicrosoftLearn","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Blog:board:MicrosoftLearnBlog":{"__typename":"Blog","id":"board:MicrosoftLearnBlog","blogPolicies":{"__typename":"BlogPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}},"boardPolicies":{"__typename":"BoardPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:AI":{"__typename":"Category","id":"category:AI","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:MicrosoftMechanics":{"__typename":"Category","id":"category:MicrosoftMechanics","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:StartupsatMicrosoft":{"__typename":"Category","id":"category:StartupsatMicrosoft","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:PartnerCommunity":{"__typename":"Category","id":"category:PartnerCommunity","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"Category:category:Windows":{"__typename":"Category","id":"category:Windows","categoryPolicies":{"__typename":"CategoryPolicies","canReadNode":{"__typename":"PolicyResult","failureReason":null}}},"QueryVariables:TopicReplyList:message:803891:173":{"__typename":"QueryVariables","id":"TopicReplyList:message:803891:173","value":{"id":"message:803891","first":10,"sorts":{"postTime":{"direction":"DESC"}},"repliesFirst":3,"repliesFirstDepthThree":1,"repliesSorts":{"postTime":{"direction":"DESC"}},"useAvatar":true,"useAuthorLogin":true,"useAuthorRank":true,"useBody":true,"useKudosCount":true,"useTimeToRead":false,"useMedia":false,"useReadOnlyIcon":false,"useRepliesCount":true,"useSearchSnippet":false,"useAcceptedSolutionButton":false,"useSolvedBadge":false,"useAttachments":false,"attachmentsFirst":5,"useTags":true,"useNodeAncestors":false,"useUserHoverCard":false,"useNodeHoverCard":false,"useModerationStatus":true,"usePreviewSubjectModal":false,"useMessageStatus":true}},"ROOT_MUTATION":{"__typename":"Mutation"},"CachedAsset:text:en_US-components/community/Navbar-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/community/Navbar-1744658876102","value":{"community":"Community Home","inbox":"Inbox","manageContent":"Manage Content","tos":"Terms of Service","forgotPassword":"Forgot Password","themeEditor":"Theme Editor","edit":"Edit Navigation Bar","skipContent":"Skip to content","gxcuf89792":"Tech Community","external-1":"Events","s-m-b":"Small and Medium Businesses","windows-server":"Windows Server","education-sector":"Education Sector","driving-adoption":"Driving Adoption","microsoft-learn":"Microsoft Learn","s-q-l-server":"SQL Server","partner-community":"Microsoft Partner Community","microsoft365":"Microsoft 365","external-9":".NET","external-8":"Teams","external-7":"Github","products-services":"Products","external-6":"Power Platform","communities-1":"Topics","external-5":"Microsoft Security","planner":"Planner","external-4":"Microsoft 365","external-3":"Dynamics 365","azure":"Azure","healthcare-and-life-sciences":"Healthcare and Life Sciences","external-2":"Azure","microsoft-mechanics":"Microsoft Mechanics","microsoft-learn-1":"Community","external-10":"Learning Room Directory","microsoft-learn-blog":"Blog","windows":"Windows","i-t-ops-talk":"ITOps Talk","external-link-1":"View All","microsoft-securityand-compliance":"Microsoft Security","public-sector":"Public Sector","community-info-center":"Lounge","external-link-2":"View All","microsoft-teams":"Microsoft Teams","external":"Blogs","microsoft-endpoint-manager":"Microsoft Intune and Configuration Manager","startupsat-microsoft":"Startups at Microsoft","exchange":"Exchange","a-i":"AI and Machine Learning","io-t":"Internet of Things (IoT)","outlook":"Outlook","external-link":"Community Hubs","communities":"Products"},"localOverride":false},"CachedAsset:text:en_US-components/community/NavbarHamburgerDropdown-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/community/NavbarHamburgerDropdown-1744658876102","value":{"hamburgerLabel":"Side Menu"},"localOverride":false},"CachedAsset:text:en_US-components/community/BrandLogo-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/community/BrandLogo-1744658876102","value":{"logoAlt":"Khoros","themeLogoAlt":"Brand Logo"},"localOverride":false},"CachedAsset:text:en_US-components/community/NavbarTextLinks-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/community/NavbarTextLinks-1744658876102","value":{"more":"More"},"localOverride":false},"CachedAsset:text:en_US-components/authentication/AuthenticationLink-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/authentication/AuthenticationLink-1744658876102","value":{"title.login":"Sign In","title.registration":"Register","title.forgotPassword":"Forgot Password","title.multiAuthLogin":"Sign In"},"localOverride":false},"CachedAsset:text:en_US-components/nodes/NodeLink-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/nodes/NodeLink-1744658876102","value":{"place":"Place {name}"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageView/MessageViewStandard-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageView/MessageViewStandard-1744658876102","value":{"anonymous":"Anonymous","author":"{messageAuthorLogin}","authorBy":"{messageAuthorLogin}","board":"{messageBoardTitle}","replyToUser":" to {parentAuthor}","showMoreReplies":"Show More","replyText":"Reply","repliesText":"Replies","markedAsSolved":"Marked as Solved","movedMessagePlaceholder.BLOG":"{count, plural, =0 {This comment has been} other {These comments have been} }","movedMessagePlaceholder.TKB":"{count, plural, =0 {This comment has been} other {These comments have been} }","movedMessagePlaceholder.FORUM":"{count, plural, =0 {This reply has been} other {These replies have been} }","movedMessagePlaceholder.IDEA":"{count, plural, =0 {This comment has been} other {These comments have been} }","movedMessagePlaceholder.OCCASION":"{count, plural, =0 {This comment has been} other {These comments have been} }","movedMessagePlaceholderUrlText":"moved.","messageStatus":"Status: ","statusChanged":"Status changed: {previousStatus} to {currentStatus}","statusAdded":"Status added: {status}","statusRemoved":"Status removed: {status}","labelExpand":"expand replies","labelCollapse":"collapse replies","unhelpfulReason.reason1":"Content is outdated","unhelpfulReason.reason2":"Article is missing information","unhelpfulReason.reason3":"Content is for a different Product","unhelpfulReason.reason4":"Doesn't match what I was searching for"},"localOverride":false},"CachedAsset:text:en_US-components/messages/ThreadedReplyList-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/ThreadedReplyList-1744658876102","value":{"title":"{count, plural, one{# Reply} other{# Replies}}","title@board:BLOG":"{count, plural, one{# Comment} other{# Comments}}","title@board:TKB":"{count, plural, one{# Comment} other{# Comments}}","title@board:IDEA":"{count, plural, one{# Comment} other{# Comments}}","title@board:OCCASION":"{count, plural, one{# Comment} other{# Comments}}","noRepliesTitle":"No Replies","noRepliesTitle@board:BLOG":"No Comments","noRepliesTitle@board:TKB":"No Comments","noRepliesTitle@board:IDEA":"No Comments","noRepliesTitle@board:OCCASION":"No Comments","noRepliesDescription":"Be the first to reply","noRepliesDescription@board:BLOG":"Be the first to comment","noRepliesDescription@board:TKB":"Be the first to comment","noRepliesDescription@board:IDEA":"Be the first to comment","noRepliesDescription@board:OCCASION":"Be the first to comment","messageReadOnlyAlert:BLOG":"Comments have been turned off for this post","messageReadOnlyAlert:TKB":"Comments have been turned off for this article","messageReadOnlyAlert:IDEA":"Comments have been turned off for this idea","messageReadOnlyAlert:FORUM":"Replies have been turned off for this discussion","messageReadOnlyAlert:OCCASION":"Comments have been turned off for this event"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageReplyCallToAction-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageReplyCallToAction-1744658876102","value":{"leaveReply":"Leave a reply...","leaveReply@board:BLOG@message:root":"Leave a comment...","leaveReply@board:TKB@message:root":"Leave a comment...","leaveReply@board:IDEA@message:root":"Leave a comment...","leaveReply@board:OCCASION@message:root":"Leave a comment...","repliesTurnedOff.FORUM":"Replies are turned off for this topic","repliesTurnedOff.BLOG":"Comments are turned off for this topic","repliesTurnedOff.TKB":"Comments are turned off for this topic","repliesTurnedOff.IDEA":"Comments are turned off for this topic","repliesTurnedOff.OCCASION":"Comments are turned off for this topic","infoText":"Stop poking me!"},"localOverride":false},"Rank:rank:37":{"__typename":"Rank","id":"rank:37","position":18,"name":"Copper Contributor","color":"333333","icon":null,"rankStyle":"TEXT"},"User:user:861143":{"__typename":"User","id":"user:861143","uid":861143,"login":"HeinHtut","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2020-11-07T09:53:23.613-08:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-6.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:861143"},"ModerationData:moderation_data:3779691":{"__typename":"ModerationData","id":"moderation_data:3779691","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:3779691":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:861143"},"id":"message:3779691","revisionNum":1,"uid":3779691,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:3779691"},"body":"

Hi Ofer_Shezaf 

can CEF collector server ingest logs which are come from \"Syslog\" format? If it is yes, how can I play around with configuration for it. 

Thanks in advance. 

Hein 

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"209","kudosSumWeight":0,"repliesCount":0,"postTime":"2023-03-27T06:17:58.427-07:00","lastPublishTime":"2023-03-27T06:17:58.427-07:00","metrics":{"__typename":"MessageMetrics","views":3076},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:3779691","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"customFields":[]},"User:user:1405100":{"__typename":"User","id":"user:1405100","uid":1405100,"login":"msagrawal15","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2022-05-27T13:15:53.374-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-10.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:1405100"},"ModerationData:moderation_data:3440417":{"__typename":"ModerationData","id":"moderation_data:3440417","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:3440417":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:1405100"},"id":"message:3440417","revisionNum":1,"uid":3440417,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:3440417"},"body":"

Hi Ofer_Shezaf,

 

Hope you are doing well.

 

We have an application hosted in Azure and the application logs are getting stored in Azure File Storage. I need to read the files from Azure File Storage and build a parser and get the logs to Azure Sentinel as a custom log source. 

 

I am relatively new to Azure and I am not sure of any custom log integrations method. Can the method mentioned here \"Custom (Azure Function)\" be used for this requirement? Do we have any other methods to integrate?

 

I have posted this as a question in the discussion forum as well.

https://techcommunity.microsoft.com/t5/microsoft-sentinel/sending-application-logs-stored-in-azure-file-storage-to-azure/m-p/3440340/highlight/true#M9592

 

Please guide.

 

Regards,

Mitesh Agrawal

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"218","kudosSumWeight":0,"repliesCount":0,"postTime":"2022-05-27T14:07:50.577-07:00","lastPublishTime":"2022-05-27T14:07:50.577-07:00","metrics":{"__typename":"MessageMetrics","views":3495},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:3440417","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"customFields":[]},"User:user:626861":{"__typename":"User","id":"user:626861","uid":626861,"login":"SvenAelterman","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2020-04-17T13:51:51.944-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS02MjY4NjEtMTkxNjg3aUMxRDkyMkM1MkJDMDdBQjY"},"rank":{"__ref":"Rank:rank:4"},"entityType":"USER","eventPath":"community:gxcuf89792/user:626861"},"ModerationData:moderation_data:2795218":{"__typename":"ModerationData","id":"moderation_data:2795218","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2795218":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:626861"},"id":"message:2795218","revisionNum":1,"uid":2795218,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2795218"},"body":"

batamig Thanks, that's the best replacement I've seen yet.

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"65","kudosSumWeight":1,"repliesCount":0,"postTime":"2021-09-29T06:27:13.663-07:00","lastPublishTime":"2021-09-29T06:27:13.663-07:00","metrics":{"__typename":"MessageMetrics","views":4570},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2795218","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"customFields":[]},"User:user:734687":{"__typename":"User","id":"user:734687","uid":734687,"login":"batamig","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2020-07-21T00:58:51.847-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS03MzQ2ODctMzEzNTAwaTkwMzE2NzFGQTJFMEEzQUI"},"rank":{"__ref":"Rank:rank:4"},"entityType":"USER","eventPath":"community:gxcuf89792/user:734687"},"ModerationData:moderation_data:2794006":{"__typename":"ModerationData","id":"moderation_data:2794006","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2794006":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:734687"},"id":"message:2794006","revisionNum":1,"uid":2794006,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2794006"},"body":"

The updated catalog of data connectors in the docs is now listed here: Find your Azure Sentinel data connector | Microsoft Docs, with details for each connector and links out to the relevant generic deployment procedures. 

\n

We'll get this blog updated with the correct link to take you directly there.
For any feedback on the doc articles, please scroll to the bottom of the page and click the Feedback link for This page to open a GitHub issue for docs. 

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"208","kudosSumWeight":1,"repliesCount":0,"postTime":"2021-09-28T22:18:36.686-07:00","lastPublishTime":"2021-09-28T22:18:36.686-07:00","metrics":{"__typename":"MessageMetrics","views":4578},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2794006","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"customFields":[]},"ModerationData:moderation_data:2641553":{"__typename":"ModerationData","id":"moderation_data:2641553","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2641553":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:626861"},"id":"message:2641553","revisionNum":1,"uid":2641553,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2641553"},"body":"

Will the Azure Sentinel Solutions catalog (Azure Sentinel solutions catalog | Microsoft Docs) be added here?

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"110","kudosSumWeight":0,"repliesCount":0,"postTime":"2021-08-12T08:50:36.340-07:00","lastPublishTime":"2021-08-12T08:50:36.340-07:00","metrics":{"__typename":"MessageMetrics","views":5042},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2641553","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}},"customFields":[]},"User:user:1098648":{"__typename":"User","id":"user:1098648","uid":1098648,"login":"DDGanti","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2021-07-08T06:01:14.724-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-10.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:1098648"},"ModerationData:moderation_data:2527916":{"__typename":"ModerationData","id":"moderation_data:2527916","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2527916":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:1098648"},"id":"message:2527916","revisionNum":1,"uid":2527916,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2527916"},"body":"

I am trying to setup a syslog injection of Nasuni auditing logs into Azure Sentinel.  I would very much appreciate if someone can point me in the right direction.

 

Thanks

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"185","kudosSumWeight":0,"repliesCount":0,"postTime":"2021-07-08T06:04:23.570-07:00","lastPublishTime":"2021-07-08T06:04:23.570-07:00","metrics":{"__typename":"MessageMetrics","views":5314},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2527916","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"User:user:276170":{"__typename":"User","id":"user:276170","uid":276170,"login":"BCoxSecureSky","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2019-01-31T13:36:01.504-08:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-4.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:276170"},"ModerationData:moderation_data:2469587":{"__typename":"ModerationData","id":"moderation_data:2469587","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2469587":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:276170"},"id":"message:2469587","revisionNum":1,"uid":2469587,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2469587"},"body":"

Guardium logging via CEF -- https://www.ibm.com/support/pages/shipping-guardium-syslog-remote-server

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"102","kudosSumWeight":0,"repliesCount":0,"postTime":"2021-06-22T07:18:11.086-07:00","lastPublishTime":"2021-06-22T07:18:11.086-07:00","metrics":{"__typename":"MessageMetrics","views":5468},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2469587","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"User:user:1020834":{"__typename":"User","id":"user:1020834","uid":1020834,"login":"JimWardJr","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2021-04-08T09:33:45.644-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-4.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:1020834"},"ModerationData:moderation_data:2366737":{"__typename":"ModerationData","id":"moderation_data:2366737","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2366737":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:1020834"},"id":"message:2366737","revisionNum":1,"uid":2366737,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2366737"},"body":"

I have a client who uses the SRT Titan SFTP Server for Azure (from Azure Marketplace), running on an Azure virtual machine. The client is implementing Sentinel and wants to ingest logs from Titan SFTP Server. The Titan server writes logs to logfiles, but I do not know the format. I have not found any information regarding data connector methods.

Can anyone provide guidance for ingesting Titan SFTP Server log data into Sentinel?

Thanks for any assistance.

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"203","kudosSumWeight":0,"repliesCount":0,"postTime":"2021-05-18T19:37:24.544-07:00","lastPublishTime":"2021-05-18T19:37:24.544-07:00","metrics":{"__typename":"MessageMetrics","views":5795},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2366737","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"User:user:943151":{"__typename":"User","id":"user:943151","uid":943151,"login":"paulbogdan","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2021-01-26T06:18:28.766-08:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-6.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:943151"},"ModerationData:moderation_data:2321857":{"__typename":"ModerationData","id":"moderation_data:2321857","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2321857":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:943151"},"id":"message:2321857","revisionNum":1,"uid":2321857,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2321857"},"body":"

Many thanks Ofer_Shezaf 

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"36","kudosSumWeight":0,"repliesCount":0,"postTime":"2021-05-04T06:42:26.213-07:00","lastPublishTime":"2021-05-04T06:42:26.213-07:00","metrics":{"__typename":"MessageMetrics","views":6016},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2321857","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"User:user:1044652":{"__typename":"User","id":"user:1044652","uid":1044652,"login":"Arunkumar_Azure","biography":null,"registrationData":{"__typename":"RegistrationData","status":null,"registrationTime":"2021-05-04T05:52:27.884-07:00"},"deleted":false,"email":"","avatar":{"__typename":"UserAvatar","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/m_assets/avatars/default/avatar-5.svg?time=0"},"rank":{"__ref":"Rank:rank:37"},"entityType":"USER","eventPath":"community:gxcuf89792/user:1044652"},"ModerationData:moderation_data:2321630":{"__typename":"ModerationData","id":"moderation_data:2321630","status":"APPROVED","rejectReason":null,"isReportedAbuse":false,"rejectUser":null,"rejectTime":null,"rejectActorType":null},"BlogReplyMessage:message:2321630":{"__typename":"BlogReplyMessage","author":{"__ref":"User:user:1044652"},"id":"message:2321630","revisionNum":1,"uid":2321630,"depth":1,"hasGivenKudo":false,"subscribed":false,"board":{"__ref":"Blog:board:MicrosoftSentinelBlog"},"parent":{"__ref":"BlogTopicMessage:message:803891"},"conversation":{"__ref":"Conversation:conversation:803891"},"subject":"Re: Azure Sentinel: The connectors grand (CEF, Syslog, Direct, Agent, Custom and more)","moderationData":{"__ref":"ModerationData:moderation_data:2321630"},"body":"

Team,

I have one question reg. SYSLOG -> Azure Sentinel setup. 

One of our customers already has SYSLOG setup in on-premise that gathers events/messages from various machines (Linux, Windows), Networking devices, and Firewalls.  

We are going to Azure Sentinel as SEIM solution, and used OMS Linux agent installed on that one machine that already consolidated logs from various machines and loaded them to Azure Sentinel. 

 

Question:

1) Is there any way that Azure Sentinel can \"Auto-discover\" hosts/device that actually sent the message and classify them as messages or events from networking device / Windows servers / Linux servers etc.,?

If not, is there any way in SYSLOG templates we need to include that tag or clue?

2) If the above is not possible, Should we recommend installing Microsoft monitoring agents in every machine/device On-premise to send events/logs to Azure sentinel individually rather than RSYSLOG?

 

Could you please share your thoughts?

","body@stripHtml({\"removeProcessingText\":false,\"removeSpoilerMarkup\":false,\"removeTocMarkup\":false,\"truncateLength\":200})@stringLength":"211","kudosSumWeight":0,"repliesCount":0,"postTime":"2021-05-04T06:02:59.752-07:00","lastPublishTime":"2021-05-04T06:02:59.752-07:00","metrics":{"__typename":"MessageMetrics","views":6017},"visibilityScope":"PUBLIC","placeholder":false,"originalMessageForPlaceholder":null,"entityType":"BLOG_REPLY","eventPath":"category:microsoft-sentinel/category:microsoft-security/category:products-services/category:communities/community:gxcuf89792board:MicrosoftSentinelBlog/message:803891/message:2321630","replies":{"__typename":"MessageConnection","pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null},"edges":[]},"customFields":[],"attachments":{"__typename":"AttachmentConnection","edges":[],"pageInfo":{"__typename":"PageInfo","hasNextPage":false,"endCursor":null,"hasPreviousPage":false,"startCursor":null}}},"CachedAsset:text:en_US-components/community/NavbarDropdownToggle-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/community/NavbarDropdownToggle-1744658876102","value":{"ariaLabelClosed":"Press the down arrow to open the menu"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/common/QueryHandler-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/common/QueryHandler-1744658876102","value":{"title":"Query Handler"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageCoverImage-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageCoverImage-1744658876102","value":{"coverImageTitle":"Cover Image"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/nodes/NodeTitle-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/nodes/NodeTitle-1744658876102","value":{"nodeTitle":"{nodeTitle, select, community {Community} other {{nodeTitle}}} "},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageTimeToRead-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageTimeToRead-1744658876102","value":{"minReadText":"{min} MIN READ"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageSubject-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageSubject-1744658876102","value":{"noSubject":"(no subject)"},"localOverride":false},"CachedAsset:text:en_US-components/users/UserLink-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/users/UserLink-1744658876102","value":{"authorName":"View Profile: {author}","anonymous":"Anonymous"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/users/UserRank-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/users/UserRank-1744658876102","value":{"rankName":"{rankName}","userRank":"Author rank {rankName}"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageTime-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageTime-1744658876102","value":{"postTime":"Published: {time}","lastPublishTime":"Last Update: {time}","conversation.lastPostingActivityTime":"Last posting activity time: {time}","conversation.lastPostTime":"Last post time: {time}","moderationData.rejectTime":"Rejected time: {time}"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageBody-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageBody-1744658876102","value":{"showMessageBody":"Show More","mentionsErrorTitle":"{mentionsType, select, board {Board} user {User} message {Message} other {}} No Longer Available","mentionsErrorMessage":"The {mentionsType} you are trying to view has been removed from the community.","videoProcessing":"Video is being processed. Please try again in a few minutes.","bannerTitle":"Video provider requires cookies to play the video. Accept to continue or {url} it directly on the provider's site.","buttonTitle":"Accept","urlText":"watch"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageCustomFields-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageCustomFields-1744658876102","value":{"CustomField.default.label":"Value of {name}"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageRevision-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageRevision-1744658876102","value":{"lastUpdatedDatePublished":"{publishCount, plural, one{Published} other{Updated}} {date}","lastUpdatedDateDraft":"Created {date}","version":"Version {major}.{minor}"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageReplyButton-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageReplyButton-1744658876102","value":{"repliesCount":"{count}","title":"Reply","title@board:BLOG@message:root":"Comment","title@board:TKB@message:root":"Comment","title@board:IDEA@message:root":"Comment","title@board:OCCASION@message:root":"Comment"},"localOverride":false},"CachedAsset:text:en_US-components/messages/MessageAuthorBio-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/messages/MessageAuthorBio-1744658876102","value":{"sendMessage":"Send Message","actionMessage":"Follow this blog board to get notified when there's new activity","coAuthor":"CO-PUBLISHER","contributor":"CONTRIBUTOR","userProfile":"View Profile","iconlink":"Go to {name} {type}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/users/UserAvatar-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/users/UserAvatar-1744658876102","value":{"altText":"{login}'s avatar","altTextGeneric":"User's avatar"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/ranks/UserRankLabel-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/ranks/UserRankLabel-1744658876102","value":{"altTitle":"Icon for {rankName} rank"},"localOverride":false},"CachedAsset:text:en_US-components/users/UserRegistrationDate-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/users/UserRegistrationDate-1744658876102","value":{"noPrefix":"{date}","withPrefix":"Joined {date}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/nodes/NodeAvatar-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/nodes/NodeAvatar-1744658876102","value":{"altTitle":"Node avatar for {nodeTitle}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/nodes/NodeDescription-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/nodes/NodeDescription-1744658876102","value":{"description":"{description}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/common/Pager/PagerLoadMorePreviousNextLinkable-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/common/Pager/PagerLoadMorePreviousNextLinkable-1744658876102","value":{"loadMore":"Show More"},"localOverride":false},"CachedAsset:text:en_US-components/tags/TagView/TagViewChip-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-components/tags/TagView/TagViewChip-1744658876102","value":{"tagLabelName":"Tag name {tagName}"},"localOverride":false},"CachedAsset:text:en_US-shared/client/components/nodes/NodeIcon-1744658876102":{"__typename":"CachedAsset","id":"text:en_US-shared/client/components/nodes/NodeIcon-1744658876102","value":{"contentType":"Content Type {style, select, FORUM {Forum} BLOG {Blog} TKB {Knowledge Base} IDEA {Ideas} OCCASION {Events} other {}} icon"},"localOverride":false}}}},"page":"/blogs/BlogMessagePage/BlogMessagePage","query":{"boardId":"microsoftsentinelblog","messageSubject":"azure-sentinel-the-connectors-grand-cef-syslog-direct-agent-custom-and-more","messageId":"803891"},"buildId":"HEhyUrv5OXNBIbfCLaOrw","runtimeConfig":{"buildInformationVisible":false,"logLevelApp":"info","logLevelMetrics":"info","openTelemetryClientEnabled":false,"openTelemetryConfigName":"o365","openTelemetryServiceVersion":"25.1.0","openTelemetryUniverse":"prod","openTelemetryCollector":"http://localhost:4318","openTelemetryRouteChangeAllowedTime":"5000","apolloDevToolsEnabled":false,"inboxMuteWipFeatureEnabled":false},"isFallback":false,"isExperimentalCompile":false,"dynamicIds":["./components/community/Navbar/NavbarWidget.tsx","./components/community/Breadcrumb/BreadcrumbWidget.tsx","./components/customComponent/CustomComponent/CustomComponent.tsx","./components/blogs/BlogArticleWidget/BlogArticleWidget.tsx","./components/external/components/ExternalComponent.tsx","./components/messages/MessageView/MessageViewStandard/MessageViewStandard.tsx","./components/messages/ThreadedReplyList/ThreadedReplyList.tsx","../shared/client/components/common/List/UnstyledList/UnstyledList.tsx","./components/messages/MessageView/MessageView.tsx","../shared/client/components/common/Pager/PagerLoadMorePreviousNextLinkable/PagerLoadMorePreviousNextLinkable.tsx","../shared/client/components/common/List/UnwrappedList/UnwrappedList.tsx","./components/tags/TagView/TagView.tsx","./components/tags/TagView/TagViewChip/TagViewChip.tsx"],"appGip":true,"scriptLoader":[{"id":"analytics","src":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/pagescripts/1730819800000/analytics.js?page.id=BlogMessagePage&entity.id=board%3Amicrosoftsentinelblog&entity.id=message%3A803891","strategy":"afterInteractive"}]}