Sentinel and data from GSuite, custom logs?


Is there any plan to integrate authentication/activity data from GSuite into Sentinel?


And - what's the plan to add custom log data (eg., LOB application logs) into Sentinel?

3 Replies

I cant answer part 1, but Log Analytics already has a Custom log feature you can enable that for the Log Analytics workspace Sentinel is using.  There is also a CEF and Syslog connector in Sentinel.

If you have Cloud App Security you can pull logs with their setup ( and then should be able to pull that into Sentinel via . It would be nice if they gave us a way to do it directly, though.