Dec 08 2022 08:13 AM
What is the best way to ensure that MDI health alerts like "Directory Services Advanced Auditing is not enabled" show as an alert in Sentinel?
Dec 15 2022 01:06 AM
There is no direct pipe for the health alerts to Sentinel.
As @Gershon Levitz suggested in the Teams channel, you could use the syslog capability in MDI to get them into a server in your environment and then forward them to Sentinel using the log analytics agent. See Connect Syslog data to Microsoft Sentinel | Microsoft Learn
Dec 15 2022 05:42 AM
Dec 18 2022 12:17 AM
Yes. Native forwarding the MDI health alerts to Sentinel is being evaluated.
Jan 02 2023 07:43 AM - edited Jan 02 2023 07:44 AM
FYI, for anyone else interested in this topic, an approach is described here https://cloudbrothers.info/en/integrate-mdi-health-alerts-microsoft-sentinel/