You can use a Jamf Security Cloud to send event data to Microsoft Sentinel.
Requirements
You need a Microsoft Sentinel subscription and the following information:
Microsoft Sentinel Workspace ID
Microsoft Sentinel Shared key
Azure Domain
Microsoft Sentinel Log Name
- In Jamf Security Cloud, navigate to .
- Click New configuration.
- Select a data stream type.
- Select Microsoft Sentinel as your data stream target type, and then click Continue.
- Configure your Microsoft Sentinel data stream:
- Enter the Microsoft Sentinel Workspace ID.
- Enter the Microsoft Sentinel Shared key.
- Choose your domain in the Azure Domain pop-up menu.
- Enter the log name in the Microsoft Sentinel Log Name field.
- Click Test Configuration.
- Use the Enable configuration switch to turn on the data stream.
- Click Save.
Events for the data stream type are sent to the configured server in real time.