Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
06Connect logs to Microsoft Sentinel7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence0/49 units complete
Learning path 06 · Connect logs to Microsoft Sentinel

7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence

0%

Study focus

Data onboarding

Select and configure connectors for Microsoft services, Defender, Windows, CEF, and Syslog sources.

Collection reliability

Plan agents, data collection rules, forwarding, destination tables, threat indicators, and ingestion validation.

7 modules · 49 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

01

Module 1

Connect data to Microsoft Sentinel using data connectors

Focus: Content Hub deployment, connector pages, provider types, collection architecture, and host validation.
0/6
01 / 06Introduction

Data connectors are Sentinel's primary mechanism for ingesting logs, alerts, incidents, entities, and threat indicators from Microsoft, third-party, and custom sources.

Official moduleConnector objectives
02 / 06Ingest log data with data connectors

Install a solution from Content Hub before configuring its connector. The connector page shows connection status, last received event, destination tables under Data types, prerequisites, instructions, and next steps such as workbooks and analytics templates.

Content Hub solutions can also install analytics rules, workbooks, hunting queries, parsers, and playbooks. Connectors can be disconnected or deactivated, but not deleted independently from the solution.

Official lessonContent Hub and connector pages
03 / 06Understand data connector providers
ProviderTypical approach
Microsoft Defender XDRIncidents, alerts, entities, and optional raw advanced-hunting events.
Azure / Microsoft servicesNative APIs, diagnostic settings, or Azure Policy.
Vendor solutionsFrequently CEF or Syslog through a Linux forwarder.
Custom dataLogs Ingestion API / DCR, Logstash output, or partner integration.

CEF is structured on top of Syslog and lands in CommonSecurityLog with normalized fields. Plain Syslog lands in Syslog, with the payload in SyslogMessage and usually requires a parser. A dedicated Azure, Arc-enabled, other-cloud, or on-premises Linux forwarder can relay CEF/Syslog.

Exam takeaway: always verify the connector's Data types; the table determines downstream KQL, analytics, and cost.
Official lessonNative, vendor, CEF, Syslog, and custom providers
04 / 06View connected hosts

Open the Sentinel workspace's Log Analytics settings, select Agents, and use the Windows or Linux tab to inspect connected hosts. From Defender, navigate through System > Settings > Microsoft Sentinel; from Azure Sentinel, use Configuration > Settings > Workspace settings.

Connector status plus actual table data and agent heartbeat provide stronger validation than host registration alone.

Official lessonAgent and host visibility
05 / 06Module assessment

Review Content Hub, connector status and data types, Microsoft versus vendor versus custom providers, CEF versus Syslog, forwarder placement, and host verification.

Official assessmentConnector fundamentals knowledge check
06 / 06Summary and resources

For every source, document its solution, connector, permissions, transport, destination table, expected volume, health signal, and downstream detections before production onboarding.

Official moduleSummary and resources
End of learning pathConnect logs to Microsoft Sentinel