Choosing the right Sentinel ingestion mechanism per source

This sheet compares Windows Security Events via AMA, Windows Forwarded Events (WEC), Activity Log diagnostic setting, Azure Policy deployIfNotExists, Logs Ingestion API.

CriterionWindows Security Events via AMAWindows Forwarded Events (WEC)Activity Log diagnostic settingAzure Policy deployIfNotExistsLogs Ingestion API
CollectsWindows security events on agent-capable machinesEvents centralised via a WEC serverSubscription Activity LogEnforces the diagnostic settingCustom REST JSON from any client

The verdict, the full comparison, 5 rules and 2 traps are part of SC-200 access. Unlock SC-200.