Valid Methods to Ingest Syslog Data into Microsoft Sentinel
Which TWO are supported methods to ingest syslog data into Microsoft Sentinel?
⚠ Common exam trap
It's easy for candidates to confuse Azure Event Hubs as a direct ingestion method for syslog data, when it is actually a transport layer that requires additional components (like a syslog collector or Logstash) to forward data to Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Common Event Format (CEF) connector
The Common Event Format (CEF) connector is a supported method because it uses a syslog daemon on a Linux log collector to receive CEF-formatted syslog messages over UDP/TCP (port 514 or 25226) and forwards them to the Log Analytics workspace via the Log Analytics agent. This connector specifically parses CEF headers and maps fields to Sentinel's schema, making it a native ingestion path for security appliances like Palo Alto Networks or Fortinet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Common Event Format (CEF) connector
Why this is correct
The Common Event Format (CEF) connector is a supported syslog ingestion method because it uses a dedicated syslog forwarder (typically a Linux VM running the CEF collector) that listens for syslog messages formatted as CEF, normalizes them, and sends them to the CommonSecurityLog table in Microsoft Sentinel. This connector natively parses the key/value pairs in CEF and maps them to standard fields, making it a first-class, documented integration for security devices that emit syslog in CEF format.
- ✗
Logstash output plugin
Why it's wrong here
A Logstash output plugin is not a supported method for ingesting syslog into Microsoft Sentinel. While Logstash can be configured to send data to Azure services via the HTTP Data Collector API or Event Hubs, there is no native Logstash output plugin specifically for Microsoft Sentinel that accepts raw syslog streams, and Sentinel does not provide a direct Logstash endpoint. Therefore, relying on Logstash alone would require custom intermediate components and does not represent an officially supported syslog connector.
- ✗
Azure Event Hubs
Why it's wrong here
Azure Event Hubs is not a supported method for direct syslog ingestion because Event Hubs is a scalable streaming platform, not a syslog receiver. To get syslog data into Event Hubs, you would need an external forwarder or agent to convert syslog to Event Hubs-compatible messages, and Microsoft Sentinel's Event Hubs connector is designed for Azure services and custom applications, not for parsing syslog in its native format. This makes it an indirect and unsupported approach for syslog ingestion.
- ✓
Syslog connector using Azure Monitor Agent (AMA)
Why this is correct
The Syslog connector using Azure Monitor Agent (AMA) is a supported and modern method for ingesting syslog data. The AMA is installed on a Linux VM, and with a data collection rule (DCR) that includes the syslog data source, it listens on TCP/UDP ports for RFC 3164 and RFC 5424 formatted messages, forwards them to a Log Analytics workspace, and populates the Syslog table. This connector is the recommended replacement for the legacy Log Analytics agent and provides a fully supported configuration for syslog ingestion.
- ✗
Direct Azure Monitor Agent ingestion without connector
Why it's wrong here
Direct Azure Monitor Agent ingestion without a connector is not supported because the Azure Monitor Agent lacks built-in syslog capabilities on its own; it must be configured with a Data Collection Rule (DCR) that specifies the syslog data source and destination, and even then it is typically set up through the Sentinel Syslog connector interface. Without a proper connector or DCR configuration, the AMA cannot accept or forward syslog traffic, so any syslog-to-AMA pipeline requires that connector layer to function correctly.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.