Nov 07 2022 04:49 AM - edited Nov 07 2022 08:40 AM
there is nothing coming up in sentinel with query SecurityEvent.
AMA connector says "Disconnected" however i created DCR from log analytic workspace => Agent management.( all are azure virtual machines ) so i believe ARC is not required.
Connector "Security Events via Legacy Agent" shows connected automatically , not the "Windows Security Events via AMA"
Nov 07 2022 07:43 AM
Nov 07 2022 07:53 AM
Nov 07 2022 08:11 AM
@Victor1989 Is the DCR listed, I don't have any but if I did, they would be below? If they are not here then we know Sentinel is unable to see them, may they're aligned to another workspace or RG?
Nov 07 2022 08:28 AM
@Clive_Watson they are not listed
but they are there in correct subscription / RG though agent management