Forum Discussion

roadruner's avatar
roadruner
Copper Contributor
Nov 03, 2020

windows DHCP server logs to Sentinel

Does anyone know how to ingest Windows DHCP server logs to Sentinel ? thanks
  • GaryBushey's avatar
    Nov 03, 2020
    One way is to install the Microsoft Monitoring agent on the servers and then in Azure Sentinel go to Settings => Workspace settings => Advanced Settings => Data and in the Windows Event Logs, select any of the DHCP event logs you want to ingest

Resources