Microsoft Sentinel tables and associated connectors

The following table lists the tables ingested into Microsoft Sentinel via data connectors, and the connectors that ingest them. Select the table name or the connector name for more information.

Table Connectors Supports DCR
AADManagedIdentitySignInLogs Microsoft Entra ID Yes
AADNonInteractiveUserSignInLogs Microsoft Entra ID Yes
AADProvisioningLogs Microsoft Entra ID Yes
AADRiskyServicePrincipals Microsoft Entra ID Yes
AADRiskyUsers Microsoft Entra ID Yes
AADServicePrincipalRiskEvents Microsoft Entra ID Yes
AADServicePrincipalSignInLogs Microsoft Entra ID Yes
AADUserRiskEvents Microsoft Entra ID Yes
ADFSSignInLogs Microsoft Entra ID Yes
ADOAuditLogs_CL Azure DevOps Audit Logs (via Codeless Connector Platform) Yes
ApacheHTTPServer_CL Custom logs via AMA Yes
ASimDnsActivityLogs Windows DNS Events via AMA Yes
AuditLogs Microsoft Entra ID Yes
AZFWApplicationRule Azure Firewall Yes
AZFWDnsQuery Azure Firewall Yes
AZFWFatFlow Azure Firewall Yes
AZFWFlowTrace Azure Firewall Yes
AZFWIdpsSignature Azure Firewall Yes
AZFWInternalFqdnResolutionFailure Azure Firewall Yes
AZFWNatRule Azure Firewall Yes
AZFWNetworkRule Azure Firewall Yes
AZFWThreatIntel Azure Firewall Yes
AzureActivity Azure Activity No
AzureDiagnostics Azure Firewall
Azure Key Vault
Azure Kubernetes Service (AKS)
Azure SQL Databases
Azure Web Application Firewall (WAF)
No
AzureMetrics Azure Storage Account No
CommonSecurityLog Cisco ASA/FTD via AMA Yes
DnsEvents DNS Yes
DnsInventory DNS Yes
JBossEvent_CL Custom logs via AMA No
JuniperIDP_CL Custom logs via AMA Yes
MarkLogicAudit_CL Custom logs via AMA No
meraki_CL Custom logs via AMA Yes
MongoDBAudit_CL Custom logs via AMA Yes
NetworkAccessTraffic Microsoft Entra ID Yes
NGINX_CL Custom logs via AMA Yes
OfficeActivity Microsoft 365 (formerly, Office 365) Yes
OracleWebLogicServer_CL Custom logs via AMA Yes
PaloAltoPrismaCloudAlertV2_CL Palo Alto Prisma Cloud CSPM (via Codeless Connector Framework) Yes
PostgreSQL_CL Custom logs via AMA Yes
SecurityBridgeLogs_CL Custom logs via AMA Yes
SecurityEvent Security Events via Legacy Agent
Windows Security Events via AMA
Yes
SigninLogs Microsoft Entra ID Yes
SquidProxy_CL Custom logs via AMA Yes
StorageBlobLogs Azure Storage Account Yes
StorageFileLogs Azure Storage Account Yes
StorageQueueLogs Azure Storage Account Yes
StorageTableLogs Azure Storage Account Yes
Syslog Syslog via AMA
Syslog via Legacy Agent
Yes
ThreatIntelligenceIndicator Threat intelligence - TAXII Yes
Tomcat_CL Custom logs via AMA Yes
Ubiquiti_CL Custom logs via AMA Yes
vcenter_CL Custom logs via AMA Yes
VectraStream_CL Custom logs via AMA No
WindowsEvent Windows Forwarded Events Yes
ZPA_CL Custom logs via AMA Yes