Microsoft Sentinel - Data Connector is showing as disconnected but is sending logs.

Matthew Agosta 0 Reputation points
2024-08-26T16:50:10.22+00:00

Hello everyone.

I have a client that has both the 'Common Event Format via Legacy Agent' and 'Common Event Format via AMA' Data Connectors in their Microsoft Sentinel environment. Both are sending logs to the 'CommonSecurityLog' table, but oddly the 'Common Event Format via AMA' Data Connector is reading as disconnected. It seems odd to me that the Data Connector is reading as disconnected but still sending logs into the table.

Only thing I am seeing is that the CEF via AMA Data Connector does not have a Data Collection Rule associated with it. Could that have anything to do with it?

Does anyone have any insight on this that can help? Any insight is appreciated.

Thanks! :)CEF via AMA Data Connector

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,123 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 32,311 Reputation points Microsoft Employee
    2024-09-03T05:45:34.6366667+00:00

    @Matthew Agosta Apologies for the delayed response in reviewing this post, Yes it is possible that the disconnected status of the 'Common Event Format via AMA' Data Connector is due to the lack of a Data Collection Rule associated with it. A Data Collection Rule is used to specify which logs should be collected by a Data Connector. Without a Data Collection Rule, the Data Connector may not be able to collect any logs, which could result in a disconnected status.

    Review this documentation where it states DCR is required to have logs ingested in Sentinel - https://video2.skills-academy.com/en-us/azure/sentinel/connect-cef-syslog-ama?tabs=portal#:~:text=TLS%20%E2%80%93%20syslog%2Dng-,Configure%20the%20data%20connector,-The%20setup%20process

    Feel free to reach out if you have any more questions. If you've already found a solution, please consider sharing it here to benefit other community members.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.