You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A365 Observability data connector gives richer insights into AI agent activity by bringing AI agent telemetry from A365, AI Foundry, and Copilot in the Microsoft Sentinel data lake to investigate agent behavior, tool usage, and execution with hunting, graph, and MCP workflows. Data from this connector is used to investigate AI agent behavior, tool usage, and execution in Microsoft Sentinel. If you have enabled these workflows, deactivating this connector will prevent those investigations from being performed.
66
+
67
+
**Log Analytics table(s):**
68
+
69
+
|Table|DCR support|Lake-only ingestion|
70
+
|---|---|---|
71
+
72
+
73
+
**Data collection rule support:** Not currently supported<br><br>
The Alibaba Cloud Networking data connector provides the capability to ingest [Alibaba Cloud](https://www.alibabacloud.com/) networking data into Microsoft Sentinel through the Simple Log Service (SLS) REST API. Refer to [API documentation](https://www.alibabacloud.com/help/en/sls/developer-reference/api-sls-2020-12-30-endpoint) for more information. The connector provides the ability to get VPC Flow Logs, WAF Logs, and API Gateway Logs from Alibaba Cloud.
148
+
149
+
**Log Analytics table(s):**
150
+
151
+
|Table|DCR support|Lake-only ingestion|
152
+
|---|---|---|
153
+
|`AlibabaCloudVPCFlowLogs`|No|No|
154
+
155
+
**Data collection rule support:** Not currently supported
156
+
157
+
**Prerequisites:**
158
+
159
+
-**Alibaba Cloud SLS API access**: **Alibaba Cloud Simple Log Service** access is required for the SLS API.<br><br>
The AWS Elastic Load Balancing (ELB) connector for Microsoft Sentinel allows you to ingest access logs and flow logs from AWS Application Load Balancers (ALB), Network Load Balancers (NLB), and Gateway Load Balancers (GLB) into Microsoft Sentinel. These logs provide detailed information about requests processed by your load balancers and VPC traffic flows, enabling security monitoring, threat detection, and traffic analysis.
225
+
226
+
**Log Analytics table(s):**
227
+
228
+
|Table|DCR support|Lake-only ingestion|
229
+
|---|---|---|
230
+
|`AWSALBAccessLogsData`|No|No|
231
+
232
+
**Data collection rule support:** Not currently supported
233
+
234
+
**Prerequisites:**
235
+
236
+
-**AWS IAM Role ARN and SQS Queue**: An **AWS IAM Role ARN** with cross-account access and an **SQS Queue URL** configured for S3 event notifications are required. See [AWS ELB connector documentation](/azure/sentinel/connect-aws) for setup instructions.<br><br>
237
+
</details>
238
+
239
+
---
240
+
182
241
<aname="amazon-web-services-networkfirewall-via-codeless-connector-framework"></a><details><summary>**Amazon Web Services NetworkFirewall (via Codeless Connector Framework)**</summary>
The [BitSight](https://www.BitSight.com/) Data Connector supports evidence-based cyber risk monitoring by bringing BitSight data in Microsoft Sentinel.
-**Microsoft.Web/sites permissions**: Read and write permissions to Azure Functions to create a Function App is required. For more information, see [Azure Functions](/azure/azure-functions/).
995
-
-**REST API Credentials/permissions**: BitSight API Token is required. See the documentation to [learn more](https://help.bitsighttech.com/hc/en-us/articles/115014888388-API-Token-Management) about API Token.<br><br>
The Imperva WAF Cloud data connector provides the capability to ingest logs into Microsoft Sentinel using the Imperva Log Integration via AWS S3 with SQS notifications. The connector parses CEF-formatted WAF events including access logs and security alerts for threat detection and investigation.Refer to [Imperva WAF Cloud Log Integration](https://docs.imperva.com/bundle/cloud-application-security/page/settings/log-integration.htm) for more information.
3248
+
3249
+
**Log Analytics table(s):**
3250
+
3251
+
|Table|DCR support|Lake-only ingestion|
3252
+
|---|---|---|
3253
+
|`ImpervaWAFCloud`|No|No|
3254
+
3255
+
**Data collection rule support:** Not currently supported<br><br>
3256
+
</details>
3257
+
3258
+
---
3259
+
3216
3260
<aname="infoblox-cloud-data-connector-via-ama"></a><details><summary>**Infoblox Cloud Data Connector via AMA**</summary>
The Microsoft Copilot logs connector in Microsoft Sentinel enables the seamless ingestion of Copilot-generated activity logs into Microsoft Sentinel for advanced threat detection, investigation, and response. It collects telemetry from Microsoft Copilot services - such as usage data, prompts and system responses - and ingests into Microsoft Sentinel, allowing security teams to monitor for misuse, detect anomalies, and maintain compliance with organizational policies.
4119
+
The Microsoft Copilot logs connector in Microsoft Sentinel enables seamless ingestion of Copilot-generated activity logs from M365 Copilot and Security Copilot into Microsoft Sentinel for advanced threat detection, investigation and response. It collects telemetry from Microsoft Copilot services such as usage dataand system responses and ingests into Microsoft Sentinel, allowing security teams to monitor for misuse, detect anomalies, and maintain compliance with organizational policies.
4076
4120
4077
4121
**Log Analytics table(s):**
4078
4122
@@ -6572,7 +6616,7 @@ The [Varonis Purview](https://www.varonis.com/) connector provides the capabilit
6572
6616
6573
6617
|Table|DCR support|Lake-only ingestion|
6574
6618
|---|---|---|
6575
-
|`varonisresources_CL`|No|No|
6619
+
|`VaronisResources_CL`|No|No|
6576
6620
6577
6621
**Data collection rule support:** Not currently supported
6578
6622
@@ -7071,12 +7115,12 @@ The [Zero Networks Segment](https://zeronetworks.com/) push connector allows Zer
7071
7115
7072
7116
|Table|DCR support|Lake-only ingestion|
7073
7117
|---|---|---|
7074
-
|`ZNAudit_CL`|No|No|
7075
-
|`ZNNetworkActivity_CL`|No|No|
7076
-
|`ZNIdentityActivity_CL`|No|No|
7077
-
|`ZNRPCActivity_CL`|No|No|
7118
+
|`ZNAudit_CL`|Yes|Yes|
7119
+
|`ZNNetworkActivity_CL`|Yes|Yes|
7120
+
|`ZNIdentityActivity_CL`|Yes|Yes|
7121
+
|`ZNRPCActivity_CL`|Yes|Yes|
7078
7122
7079
-
**Data collection rule support:**Not currently supported
|AWSALBAccessLogsData|[Amazon Web Services Elastic Load Balancing (via Codeless Connector Framework)](/azure/sentinel/data-connectors-reference#amazon-web-services-elastic-load-balancing-via-codeless-connector-framework)|No|No|
60
62
|AWSCloudFront_AccessLog_CL|[Amazon Web Services CloudFront (via Codeless Connector Framework) (Preview)](/azure/sentinel/data-connectors-reference#amazon-web-services-cloudfront-via-codeless-connector-framework-preview)|Yes|Yes|
61
63
|[AWSCloudTrail](/azure/azure-monitor/reference/tables/AWSCloudTrail)|[Amazon Web Services S3](/azure/sentinel/data-connectors-reference#amazon-web-services-s3)<br>[Amazon Web Services](/azure/sentinel/data-connectors-reference#amazon-web-services)|Yes|Yes|
62
64
|[AWSCloudWatch](/azure/azure-monitor/reference/tables/AWSCloudWatch)|[Amazon Web Services S3](/azure/sentinel/data-connectors-reference#amazon-web-services-s3)|Yes|Yes|
|Infoblox_Failed_Indicators_CL|[Infoblox Data Connector via REST API](/azure/sentinel/data-connectors-reference#infoblox-data-connector-via-rest-api)|No|No|
299
291
|InfobloxInsight_CL|[Infoblox SOC Insight Data Connector via REST API](/azure/sentinel/data-connectors-reference#infoblox-soc-insight-data-connector-via-rest-api)|No|No|
0 commit comments