Skip to content

Commit a296dd0

Browse files
Merge pull request #305184 from EdB-MSFT/update-sentinel-lake-connectors-xdr
updated xdr and custome logs
2 parents 0388e74 + 67107bd commit a296dd0

1 file changed

Lines changed: 9 additions & 4 deletions

File tree

articles/sentinel/datalake/sentinel-lake-connectors.md

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -36,13 +36,18 @@ To configure retention and tiering for the data connector see [Configure data co
3636

3737
## Microsoft Sentinel XDR data
3838

39-
All tables from your Microsoft Sentinel XDR connector are enabled in the data lake with 30-day retention period. Navigate to **Microsoft Sentinel** > **Configuration** > **Tables** in the Microsoft Defender portal to extend retention of the XDR tables without impacting the default retention of your analytics tier tables.
40-
41-
Non-DCR/MMA-based custom tables aren't mirrored to the data lake. DCR-based custom tables are mirrored.
39+
By default, Microsoft Defender XDR retains threat hunting data in the XDR default tier for 30 days. XDR data isn't ingested into the analytics or data lake tiers by default. Some XDR tables can be ingested into the analytics and data lake tiers by increasing the retention time to more than 30 days. For more information, see [Manage XDR data in Microsoft Sentinel](../manage-data-overview.md#manage-xdr-data-in-microsoft-sentinel).
40+
41+
42+
## Custom log tables
43+
44+
Microsoft Monitoring Agent(MMA) and Log analytics Agent (CLV1) custom tables aren't mirrored to the data lake.
45+
46+
Tables created using the Logs Ingestion API or Azure Monitor Agent (AMA) and DCR-based custom tables are mirrored. For more information, see [Logs Ingestion API in Azure Monitor](/azure/azure-monitor/logs/logs-ingestion-api-overview).
4247

4348
## Auxiliary log tables
4449

45-
When a customer has onboarded to both Defender and Microsoft Sentinel onboards to the data lake, auxiliary log tables are no longer visible in Microsoft Defender’s Advanced hunting or in the Microsoft Sentinel Azure portal. The auxiliary table data is available in the data lake and can be queried using KQL queries or Jupyter notebooks. Find KQL queries under **Microsoft Sentinel** > **Data lake exploration** in the Defender portal.
50+
When a customer has onboarded to both Defender and Microsoft Sentinel and then onboards to the data lake, auxiliary log tables are no longer visible in Microsoft Defender’s Advanced hunting or in the Microsoft Sentinel Azure portal. The auxiliary table data is available in the data lake and can be queried using KQL queries or Jupyter notebooks. Find KQL queries under **Microsoft Sentinel** > **Data lake exploration** in the Defender portal.
4651

4752

4853
## Related articles

0 commit comments

Comments
 (0)