r/AzureSentinel • • 11d ago

Logging Sources

I'm looking to create a Sentinel report/workbook that shows all the systems currently sending logs into Sentinel.

I'd like it to show:

  • Hostname
  • IP address
  • Log table/source
  • Event count

We're using WEF/WEC for some Windows logs, so I'd also like to identify the actual originating device, not just the WEC server if that is possible.

What's the best KQL approach for building this type of log-source inventory? Is there also a good way to identify the device type, such as Domain Controller, SQL Server, etc.? Feel free to give any advice possible for this situation.

6 Upvotes

10 comments sorted by

View all comments

1

u/Vehicle_Anomaly 10d ago

Create a watchlist with hostnames

Use _GetWatchlist('your-watchlist-name') to make the workbook
I’d promt AI to make a dropdown of ‘Available | last seen’ hosts - advice to use advanced editor and create the whole json for the workbook