Microsoft Sentinel Prerequisites and Field Values - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Microsoft Sentinel uses a data ingestion API to integrate with Jamf Security Cloud.

Prerequisites

A Microsoft Sentinel subscription

Field Values

The following field values are required to establish the data stream integration with Microsoft Sentinel:

Data collection endpoint
To find yours in your Azure portal, go toMonitor > Data Collection Endpoints > your DCE > Logs Ingestion URI .
Data collection rule ID
To find yours in your Microsoft Azure portal, go to Monitor > Data Collection Rules > your DCR > JSON View > immutableId. The format is dcr-xxxxxxxxxxxxxxxx.
Stream name
To find yours in your Microsoft Azure portal, go to Monitor > Data Collection Rules > your DCR > JSON View > streamDeclarations. The format is Custom-TableName_CL.
Tenant ID
To find yours in your Microsoft Azure portal, go to Entra ID > Overview > Basic Information > Tenant ID.
Client ID
To find yours in your Microsoft Azure portal, go to Entra ID > App Registrations > your app > Overview.
Client secret
To find yours in your Microsoft Azure portal, go to Entra ID > App Registrations > your app > Certificates & Secrets > Value.