
Episode 8 of 10
For the full video series, click here: https://aka.ms/SC-200onYouTube
This video focuses on how to connect and ingest log data into Microsoft Sentinel at cloud scale, giving Security Operations Analysts the skills to onboard diverse data sources and build a rich foundation for threat detection and investigation. It covers the full range of ingestion methods—using built‑in data connectors for Microsoft services, integrating Microsoft Defender XDR, onboarding Windows event logs and Sysmon, configuring Common Event Format (CEF) and Syslog ingestion for third‑party solutions, and connecting threat intelligence indicators—while also showing how to view connected hosts and validate data flow. Together, these modules help learners understand the architectural considerations, configuration steps, and operational practices required to unify logs from on‑premises, Azure, and multicloud environments, aligning directly with the competencies measured in the SC‑200: Microsoft Security Operations Analyst certification.
Learn more about this course and take the certification exam to test your new skills: https://aka.ms/SC-200onLearn











