- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Use Observability Pipelines’ Microsoft Sentinel destination to send logs to Microsoft Sentinel.
Set up the Microsoft Sentinel destination and its environment variables when you set up a pipeline. The information below is configured in the pipelines UI, except for Prerequisites which provides instructions on how to find the information you need in Microsoft Azure.
To set up the Microsoft Sentinel destination, you need to create a Workspace in Azure if you haven’t already. In that workspace:
Custom-MyLogs_CL
).Custom-
. CL
is automatically appended to the end of the table name. You need the table name to set up the Observability Pipelines Microsoft Sentinel destination.TimeGenerated
is required:{
"TimeGenerated": "2024-07-22T11:47:51Z",
"event": {}
}
The table below summarizes the Azure and Microsoft Sentinel information you need when you set up the Observability Pipelines Microsoft Sentinel destination:
Name | Description |
---|---|
Application (client) ID | The Azure Active Directory (AD) application’s client ID. See Register an application in Microsoft Entra ID for more information. Example: 550e8400-e29b-41d4-a716-446655440000 |
Directory (tenant) ID | The Azure AD tenant ID. See Register an application in Microsoft Entra ID for more information. Example: 72f988bf-86f1-41af-91ab-2d7cd011db47 |
Table (Stream) Name | The name of the stream which matches the table chosen when configuring the Data Collection Rule (DCR). Note: The table name must start with Custom- . CL is automatically appended to the end of the table name.Example: Custom-MyLogs_CL |
Data Collection Rule (DCR) immutable ID | This is the immutable ID of the DCR where logging routes are defined. It is the Immutable ID shown on the DCR Overview page. Note: Ensure the Monitoring Metrics Publisher role is assigned in the DCR IAM settings. Example: dcr-000a00a000a00000a000000aa000a0aa See Data collection rules (DCRs) in Azure Monitor to learn more about creating or viewing DCRs. |
To set up the Microsoft Sentinel destination in Observability Pipelines:
550e8400-e29b-41d4-a716-446655440000
.72f988bf-86f1-41af-91ab-2d7cd011db47
. This is the Azure AD tenant ID.Custom-MyLogs_CL
.dcr-000a00a000a00000a000000aa000a0aa
.https://<DCE-ID>.ingest.monitor.azure.com
.DD_OP_DESTINATION_MICROSOFT_SENTINEL_DCE_URI
550e8400-e29b-41d4-a716-446655440000
.DD_OP_DESTINATION_MICROSOFT_SENTINEL_CLIENT_SECRET
A batch of events is flushed when one of these parameters is met. See event batching for more information.
Max Events | Max Bytes | Timeout (seconds) |
---|---|---|
None | 10,000,000 | 1 |