Microsoft Sentinel
Cloud and workloads

Configure Data Transformation

In brief

The article now labels the data collection rule reference section, clarifies which DCR procedures require verification, and warns that deleting the legacy table and custom data connector is irreversible and may affect existing queries, workbooks, or integrations.

What Defender admins need to know

Review dependencies before deleting legacy resources, especially where existing queries, workbooks, or integrations reference them.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to configure ingestion-time data transformation and custom log ingestion so that I can control, filter, and enrich data before it is ingested into Microsoft Sentinel.

More on dataData collection rulesrule structure and transformation reference

For more information, see data collection rules:

After you complete one of thea Log Ingestion API or workspace transformation DCR configuration procedures linked above,procedure, return to Microsoft Sentinel to verify that your data is being ingested based on the transformation you configured. It may take up to 60 minutes for the data transformation configurations to apply.

Migrate to ingestion-time data transformation

  • Configure a DCR to define, from scratch, the custom ingestion from your data source to a new table. You might use this option if you want to use a new schema that doesn't have the current column suffixes, and doesn't require query-time Kusto Query Language (KQL) functions to standardize your data.

    After you've verified that your data is properly ingested to the new table, you can delete the legacy table, as well as your legacy, custom data connector.

  • Continue using the custom table created by your custom data connector. You might use this option if you have a lot of custom security content created for your existing table. In such cases, see Migrate from Data Collector API and custom fields-enabled tables to DCR-based custom logs

After you've verified that your data is properly ingested to the new table, you can delete the legacy table, as well as your legacy, custom data connector.