We are in the process of migrating from MMA to AMA. We have prepared a central security DCR which collects Security Events and a association policy to make sure new subscription and VM's are automatically associated with the DCR.
However in the Sentinel 'Windows Security Events via AMA' dataconnector I cannot select the existing DCR.
I suppose I have to create the DCR via Sentinel but that poses new challenges:
- how to automatically onboard new subscriptions ot this DCR (I cannot select a managementgroup at sources)
- how to deploy this in code
Is there a way to connect the data connector to an existing DCR rule?