Feb 08 2022 07:06 AM
Hi,
I'm trying to export all the connectors (both connected and not) for review.
I've experimented with the Powershell module, az.securityinsights, which does give me the command get-AzSentinelDataConnector. However this only produces the following:-
AzureSecurityCenter
AzureActiveDirectory
AzureAdvancedThreatProtection
MicrosoftCloudAppSecurity
MicrosoftDefenderAdvancedThreatProtection
Office365
ThreatIntelligence
yet there are 125 in total.
What might I be doing wrong ?
Thanks,
Jamie
Feb 08 2022 08:52 AM
Feb 08 2022 08:56 AM
Feb 08 2022 09:11 AM
Solution
Not via 'Connector' that I'm aware of, its why most of the reports are done per Table instead (which isn't a 1 to 1 mapping to Connector)
Take a look at Workbooks: Workspace Usage or Data Collection Health Monitoring for Table examples.
In "Workspace Usage" - Weekly Report tab, you can see the Connector vs, Tables mapping but only where there is a Rule Template and its per Rule.
Sentinel Health (Preview) may support this eventually?
Monitor the health of your Microsoft Sentinel data connectors | Microsoft Docs
Feb 09 2022 12:09 AM
Feb 08 2022 09:11 AM
Solution
Not via 'Connector' that I'm aware of, its why most of the reports are done per Table instead (which isn't a 1 to 1 mapping to Connector)
Take a look at Workbooks: Workspace Usage or Data Collection Health Monitoring for Table examples.
In "Workspace Usage" - Weekly Report tab, you can see the Connector vs, Tables mapping but only where there is a Rule Template and its per Rule.
Sentinel Health (Preview) may support this eventually?
Monitor the health of your Microsoft Sentinel data connectors | Microsoft Docs