Projects
CybersecurityInternal System

Sentinel Log Ingestion

Non-native telemetry into Microsoft Sentinel

January 2026 – June 2026

Microsoft SentinelKQLAzureCEFLog Analytics

Problem

Security telemetry that Sentinel does not natively understand still has to land in useful tables for detection work.

Approach

Designed DCRs, custom tables, and schemas, then a syslog pipeline for Palo Alto logs with CEF forwarding and severity-based filtering.

Outcome

Ingestion accuracy validated with KQL schema checks and cross-source correlation in Log Analytics.

  • Built log ingestion pipelines in Microsoft Sentinel via DCRs, custom tables, and schemas for non-native telemetry
  • Architected a syslog pipeline for Palo Alto firewall logs via CEF forwarding with severity-based filtering
  • Validated ingestion accuracy via KQL schema checks and cross-source correlation in Log Analytics

Related experience: Cybersecurity Co-op · Shaw Industries