- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Use Observability Pipelines’ Microsoft Sentinel destination to send logs to Microsoft Sentinel.
Set up the Microsoft Sentinel destination and its environment variables when you set up a pipeline. The information below is configured in the pipelines UI, except for Prerequisites which provides instructions on how to find the information you need in Microsoft Azure.
To set up the Microsoft Sentinel destination, you need the following information:
Name | Description |
---|---|
Application (client) ID | The Azure Active Directory (AD) application’s client ID. See Register an application in Microsoft Entra ID for information on creating a new application. Example: 550e8400-e29b-41d4-a716-446655440000 |
Directory (tenant) ID | The Azure AD tenant ID. See Register an application in Microsoft Entra ID for information on creating a new application. Example: 72f988bf-86f1-41af-91ab-2d7cd011db47 |
Table (Stream) Name | The name of the stream which matches the table chosen when configuring the Data Collection Rule (DCR). Example: Custom-MyLogs_CL |
Data Collection Rule (DCR) immutable ID | This is the immutable ID of the DCR where logging routes are defined. It is the Immutable ID shown on the DCR Overview page. Note: Ensure the Monitoring Metrics Publisher role is assigned in the DCR IAM settings. Example: dcr-000a00a000a00000a000000aa000a0aa See Data collection rules (DCRs) in Azure Monitor to learn more about creating or viewing DCRs. |
Do the following to get that information:
Custom-MyLogs_CL
) in the DCR, which is where Observability Pipelines sends logs to.https://<DCE-ID>.ingest.monitor.azure.com/dataCollectionRules/<DCR-Immutable-ID>/streams/<Stream-Name>?api-version=2023-01-01
, where the <Stream-Name>
typically matches your custom table (for example, Custom-MyLogs_CL
).To set up the Microsoft Sentinel destination in Observability Pipelines:
550e8400-e29b-41d4-a716-446655440000
.72f988bf-86f1-41af-91ab-2d7cd011db47
. This is the Azure AD tenant ID.Custom-MyLogs
, to which you are sending logs.dcr-000a00a000a00000a000000aa000a0aa
.https://<DCE-ID>.ingest.monitor.azure.com/dataCollectionRules/<DCR-Immutable-ID>/streams/<Stream-Name>?api-version=2023-01-01
.DD_OP_DESTINATION_MICROSOFT_SENTINEL_DCE_URI
550e8400-e29b-41d4-a716-446655440000
.DD_OP_DESTINATION_MICROSOFT_SENTINEL_CLIENT_SECRET
A batch of events is flushed when one of these parameters is met. See event batching for more information.
Max Events | Max Bytes | Timeout (seconds) |
---|---|---|
None | 10,000,000 | 1 |