Microsoft Sentinel uses a data ingestion API to integrate with Jamf Security Cloud.
Prerequisites
A Microsoft Sentinel subscription
Field Values
The following field values are required to establish the data stream integration with Microsoft Sentinel:
- Data collection endpoint
- To find yours in your Azure portal, go to .
- Data collection rule ID
- To find yours in your Microsoft Azure portal, go to . The format is
dcr-xxxxxxxxxxxxxxxx. - Stream name
- To find yours in your Microsoft Azure portal, go to . The format is
Custom-TableName_CL. - Tenant ID
- To find yours in your Microsoft Azure portal, go to .
- Client ID
- To find yours in your Microsoft Azure portal, go to .
- Client secret
- To find yours in your Microsoft Azure portal, go to .