Choosing the right Sentinel ingestion mechanism per source
This sheet compares Windows Security Events via AMA, Windows Forwarded Events (WEC), Activity Log diagnostic setting, Azure Policy deployIfNotExists, Logs Ingestion API.
| Criterion | Windows Security Events via AMA | Windows Forwarded Events (WEC) | Activity Log diagnostic setting | Azure Policy deployIfNotExists | Logs Ingestion API |
|---|---|---|---|---|---|
| Collects | Windows security events on agent-capable machines | Events centralised via a WEC server | Subscription Activity Log | Enforces the diagnostic setting | Custom REST JSON from any client |
The verdict, the full comparison, 5 rules and 2 traps are part of SC-200 access. Unlock SC-200.