SC‑300 Study Portal Path 5

Unit 5: Export logs to a third-party security information and event management (SIEM) system

Organizations often use third-party SIEM tools to centralize security monitoring across cloud and on-premises environments. Microsoft Entra ID and Azure services support this by exporting logs through Azure Monitor, which acts as the unified logging pipeline.

Azure Monitor as the central logging pipeline

Since the introduction of Azure Monitor, Microsoft has consolidated logging across Azure services into a single, standardized pipeline.

Key points

Recommended SIEM integration architecture

Microsoft recommends integrating third-party SIEM tools using Azure Event Hubs.

Why Azure Event Hubs?

Azure Event Hubs provides a:

Recommended flow

This is the Microsoft-recommended approach for SIEM integration going forward.

SIEM partner integrations

Microsoft has partnered with major SIEM vendors to build native connectors that consume logs from Azure Event Hubs.

Supported SIEM integrations

SIEM ToolRecommended integration
SplunkAzure Monitor Add-On for Splunk
IBM QRadarMicrosoft Azure DSM + Azure Event Hubs Protocol
ArcSightArcSight Azure Event Hubs Smart Connector

These connectors are designed to:

Azure Log Integration tool (AzLog)

What was AzLog?

Current status of AzLog

SIEM integration recommendations

Use the table below to determine the correct approach based on your SIEM tool and current state.

Migration guidance

SIEM ToolCurrently using AzLogEvaluating SIEM integration
SplunkMigrate to Azure Monitor Add-On for SplunkUse Azure Monitor Add-On for Splunk
IBM QRadarMigrate to Azure DSM + Event Hubs ProtocolUse Azure DSM + Event Hubs Protocol
ArcSightUse ArcSight Azure Event Hubs Smart ConnectorUse ArcSight Azure Event Hubs Smart Connector

Only SIEM tools that were officially supported by AzLog are included here.

Integration roadmap and current gaps

Azure Monitor does not yet cover all AzLog capabilities. Microsoft has identified the following gaps and roadmap items.

Known gaps

Integration with other SIEM tools

AzLog supported exporting standardized JSON logs to disk, enabling integration with SIEM tools that were not officially supported.

Current recommendation

Security and scalability considerations

Exam-focused summary (Unit 5)