Skip to main contentSkip to main content
The Red Raffle banner icon.

The Jr Pentester Path just got rebuilt. Complete rooms, earn tickets, and win a free PT1 cert.

Room Banner
Back to all walkthroughs
Room Icon

MS Sentinel: Ingest Data

Premium room

No logs, no correlation, no analysis, no action. Where is my log data?

easy

60 min

603

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In the previous MS Sentinel: Deploy room, we deployed an instance of Microsoft Sentinel. The next logical phase is to plan and execute the log data ingestion process. In Microsoft Sentinel, logs are sent to Log Analytics workspaces via data connectors.

As a Microsoft Security Analyst, it is essential to know how to connect log data from different sources. The organization may have data from Microsoft and non-Microsoft resources as well as on-premise and network appliances.

Learning Objectives

In this room, we will look into the options for ingesting data and how to connect them so that Microsoft Sentinel starts to analyze and correlate logs. The main parts of this room will be:

  • Data connectors
  • Content hub solutions
  • How to install Content hub solutions
  • How to connect data connectors

Let's dive in!

Answer the questions below
What is used to ingest log data into Microsoft Sentinel?