Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Azure Log Analytics Connection #44

Open
thiagoist opened this issue Jul 30, 2021 · 2 comments
Open

Add Azure Log Analytics Connection #44

thiagoist opened this issue Jul 30, 2021 · 2 comments

Comments

@thiagoist
Copy link

Issue Type: Feature Request

Would be awesome if we could create an azure sentinel log analytics workspace connection.

@dotnvo
Copy link

dotnvo commented Nov 11, 2022

+1 on this. This is a great little tool and I have been using it for Kusto Detective Agency! We ingest logs at work into LA/Sentinel and I'd love to be able to query those without opening up sentinel sometimes.

You can technically add AI/LA workspaces to azure data explorer.. but our environment we can't create those clusters. For Kusto Detective Agency I it seems like you should be able to also connect to these sources/clusters directly.

Query data in Azure Monitor using Azure Data Explorer explains how you can connect to a LA workspace which likely works - it's basically this URL:

https://ade.loganalytics.io/subscriptions//resourcegroups//providers/microsoft.operationalinsights/workspaces/

everything after https://ade.loganalytics.io is just the resource ID of the Log Analytics workspace. It seems like this would be possible. I tried but there's clearly some error checking going on here that's being triggered

@wbrguerra
Copy link

wbrguerra commented Jan 19, 2025

+1. I wanted to bump this due to how prevalent Sentinel/LAW has become over the past several years. Having the ability to query Sentinel data would be an extremely positive benefit to the MANY security teams that rely on Sentinel in daily operations. Thank you @DonJayamanne for this extension, it has become a staple for querying data in ADX.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants