You are investigating a series of failed logon attempts across multiple on-premises servers. You want to use Microsoft Sentinel to hunt for patterns of brute-force attacks. Which data source should you ingest to capture detailed authentication events from domain controllers?
Windows Security Events, collected via Windows Event Forwarding (WEF), are the authoritative source for on-premises failed-logon hunting because domain controllers log Event ID 4625 for every failed NTLM/Kerberos logon attempt. WEF uses HTTP/HTTPS (WinRM) and a collector-initiated subscription, preserving the full payload: source IP address, workstation name, logon type, and authentication package. This enables centralized correlation across all DCs in the domain and direct ingestion into a SIEM such as Sentinel.
Why this answer
Windows Security Events from domain controllers, collected via Windows Event Forwarding (WEF) or directly, include Event ID 4625 (failed logon) and other authentication events necessary for brute-force hunting. Option A is incorrect because Syslog from domain controllers does not capture Windows Security Events; Syslog is typically used for network devices or Linux systems. Option C is incorrect because Azure Activity Log records Azure resource management operations, not on-premises authentication events.
Option D is incorrect because Microsoft 365 Defender events cover cloud and endpoint alerts but not detailed authentication logs from on-premises domain controllers.