Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | Security - Threat Protection |
| Version | 3.0.13 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2022-05-23 |
| Last Updated | 2026-08-07 |
| Solution Folder | Windows Security Events |
| Marketplace | Azure Marketplace · Rating: ★★★☆☆ 3.0/5 (4 ratings) · Popularity: 🟢 High (95%) |
The Windows Security Events solution for Microsoft Sentinel allows you to ingest Security events from your Windows machines using the Windows Agent into Microsoft Sentinel. This solution includes two (2) data connectors to help ingest the logs.
Windows Security Events via AMA - This data connector helps in ingesting Security Events logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent here. Microsoft recommends using this Data Connector.
Security Events via Legacy Agent - This data connector helps in ingesting Security Events logs into your Log Analytics Workspace using the legacy Log Analytics agent.
Additional Information
📖 Setup Guide: Windows security events via AMA - Collect Windows security events using Azure Monitor Agent
This solution provides 2 data connector(s):
This solution uses 4 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
DeviceProcessEvents |
- | Analytics |
Event |
- | Analytics, Hunting |
SecurityEvent |
Security Events via Legacy Agent, Windows Security Events via AMA | Analytics, Hunting, Workbooks |
WindowsEvent |
- | Hunting |
This solution includes 73 content item(s):
| Content Type | Count |
|---|---|
| Hunting Queries | 50 |
| Analytic Rules | 21 |
| Workbooks | 2 |
| Name | Tables Used |
|---|---|
| EventAnalyzer | SecurityEvent |
| IdentityAndAccess | SecurityEvent |
| Version | Date Modified (DD-MM-YYYY) | Change History | |-------------|--------------------------------|--------------------------------------------------------------------------------------------| | 3.0.13 | 20-07-2026 | Added Analytic Rule WMI Spawning Suspicious Child Process | | 3.0.12 | 18-02-2026 | Removed external blog reference text from "Remote Scheduled Task Creation or Update using ATSVC Named Pipe" and " Scheduled Task Creation or Update from User Writable Directory" hunting query description | | 3.0.11 | 28-01-2026 | Updated Analytic Rule to fix the link from the description & Update Analytic Rule NonDCActiveDirectoryReplication - to reduce false positive results | | 3.0.10 | 12-01-2026 | Update Analytic Rule NonDCActiveDirectoryReplication - fix swapped fields | | 3.0.9 | 01-10-2024 | Removed kind from Hunting Query [Service installation from user writable directory] | | 3.0.8 | 23-07-2024 | Updated the Workspace type from resource type picker to resource picker in Workbook | | 3.0.7 | 12-06-2024 | Fixed the bugs from Analytic Rules NRT_execute_base64_decodedpayload.yaml and ADFSRemoteAuthSyncConnection.yaml | | 3.0.6 | 16-05-2024 | Fixed wrong fieldMappings of Analytic Rules password_not_set.yaml | | 3.0.5 | 21-03-2024 | Updated Entity Mappings of Analytic Rules | | | 3.0.4 | 06-03-2024 | Added New Hunting Queries | | 3.0.3 | 19-02-2024 | Updated Entity Mapping in Analytical Rule [Non Domain Controller Active Directory Replication] | | 3.0.2 | 23-01-2024 | Added Sub-Technique in Template | | 3.0.1 | 13-12-2023 | Updated query in Analytical Rule (AD user enabled and password not set within 48 hours)| | 3.0.0 | 26-12-2023 | Modified text as there is rebranding from Azure Active Directory to Microsoft Entra ID. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊