Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
06Connect logs to Microsoft Sentinel7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence0/49 units complete
Learning path 06 · Connect logs to Microsoft Sentinel

7 modules · 49 units · Content Hub, Microsoft services, Defender, Windows, CEF, Syslog, and threat intelligence

0%

Study focus

Data onboarding

Select and configure connectors for Microsoft services, Defender, Windows, CEF, and Syslog sources.

Collection reliability

Plan agents, data collection rules, forwarding, destination tables, threat indicators, and ingestion validation.

7 modules · 49 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

05

Module 5

Connect Common Event Format logs to Microsoft Sentinel

Focus: CEF via AMA, Linux forwarder design, DCR creation, secure transport, and duplicate prevention.
0/5
01 / 05Introduction

CEF provides a vendor-neutral structured event format over Syslog. Sentinel parses CEF events into CommonSecurityLog, enabling consistent fields across supported security appliances.

Official moduleCEF objectives
02 / 05Plan for Common Event Format connector

CEF via AMA uses a dedicated 64-bit Linux forwarder in Azure, another cloud, or on-premises. Network appliances send CEF/Syslog to rsyslog or syslog-ng; AMA sends the parsed events securely to the Sentinel workspace.

Harden the forwarder, restrict network paths, and configure TLS between sources and forwarder where required. Supported distributions, daemon versions, RFC 3164/5424, sudo permissions, connectivity, and capacity must be validated against current documentation.

Official lessonForwarder architecture and prerequisites
03 / 05Connect your external solution using the CEF connector
  1. Open CEF via AMA and create a DCR.
  2. Select the Linux forwarder resource; AMA installs automatically if absent.
  3. Configure facilities and minimum severities.
  4. Point appliances to the forwarder's TCP or UDP 514 listener.
  5. Validate CommonSecurityLog records and connector health.

If one forwarder handles both CEF and plain Syslog, exclude CEF facilities from the Syslog configuration to prevent duplicate rows in Syslog and CommonSecurityLog.

Official lessonCEF DCR and appliance forwarding
04 / 05Module assessment

Review forwarder placement, AMA and DCR responsibilities, Linux and daemon prerequisites, TLS, port 514, facilities and severities, destination table, and duplicate prevention.

Official assessmentCEF knowledge check
05 / 05Summary and resources

CEF is preferable when the vendor supports it because fields arrive normalized. Secure and monitor the forwarder as critical collection infrastructure.

Official moduleSummary and resources
End of learning pathConnect logs to Microsoft Sentinel