Connect Windows Hosts to Azure Sentinel
Plan for Windows Hosts Security Events Connector The Security Events connector lets you stream all security events from your Windows systems to your Azure Sentinel workspace. You can select which event to stream from among the following sets: All events- All Windows security and AppLocker events. Common- A standard set of events for auditing purposes. A full user audit trail is included in this set. There are also auditing actions such as security group changes, key domain controller Kerberos operations, and other types of events in line with accepted best practices. The Common event set may contain some types of events that aren't so common. This is because the main point of the Common set is to reduce the volume of events to a more manageable level while still maintaining full audit trail capability. Minimal- A small set of events that might indicate potential threat. This set does not contain a full audit trail. It covers only the events that might indicate a successful ...