SIEM Integration - Microsoft Sentinel DCE

This article details the steps to set up your integration with Microsoft Sentinel DCE and Sharetru.

Note: Do not toggle the Enable to "on" until you have filled out the form illustrated below and completed a test of the connection.


Use the SIEM "Select Service..." dropdown and select Microsoft Sentinel DCE.
image-20240715-224939

The only Format available for Microsoft Sentinel DCE is JSON.
image-20240715-232203

To view an example of the SIEM test message click the link button.
image-20240715-234247

Enter your Azure Directory (tenant) ID: See example below
image-20240715-233430

Enter the application (client) ID registered in your Entra instance: See example below
image-20240715-234344

Enter the value of the Application secret for the registered app: See example below
image-20240715-234416

Enter the DCE or the DCR endpoint for the Log Analytics workspace: See example below
image-20240715-234446

Enter the DCR ID from Azure Log Analytics: See example below

image-20240715-234540

Enter the Stream Name in the DCR that should handle the custom data: See example below
image-20240715-234606

Toggle this option on to send data to the GCC high region:
image-20240715-234659(1)

After the form is completed click "Save".

image-20240715-201420

Now, you will need to test the connection. Click the "Test Connection" button.
image-20240715-201448


If the connection is successful you will receive a message verifying that result.
image (2)-1

*You should verify that the message was received by your Microsoft Sentinel DCE instance. *

However, if the connection is not successful you will receive a message regarding the failure. 

Upon successfully completing the test you may toggle the "Enable" switch on and then click "Save".

This will finalize the SIEM integration set up.image-20240715-203324

image-20240716-213829(1)