Forum Discussion
Dean_Gross
Dec 08, 2022Silver Contributor
MDI Health Alerts - Send to Sentinel
What is the best way to ensure that MDI health alerts like "Directory Services Advanced Auditing is not enabled" show as an alert in Sentinel?
- Martin_SchvartzmanMicrosoft
There is no direct pipe for the health alerts to Sentinel.
As GershonLevitz-MSFT suggested in the Teams channel, you could use the syslog capability in MDI to get them into a server in your environment and then forward them to Sentinel using the log analytics agent. See Connect Syslog data to Microsoft Sentinel | Microsoft Learn
- Dean_GrossSilver ContributorThanks for the workaround, are there any plans to add this basic functionality? I don't think that we should have to do extra work like this after we have already configured the sensors and since the health data is already visible in M365 Security center
- Martin_SchvartzmanMicrosoft
Yes. Native forwarding the MDI health alerts to Sentinel is being evaluated.