How do I get windows firewall logs my workspace?

F S 0 Reputation points
2025-03-11T19:02:46.3033333+00:00

I have a W11 endpoint, not a VM btw. I deployed AMA through Intune. AMA is running fine. My workspace is only showing Heartbeat logs for the endpoint.

I need FW logs. I made sure public, private & domain profiles are enabled on my endpoint. I made sure logging for successful & dropped packets are enabled on all profiles too. I checked my firewall logs and there are firewall logs accumulating.

I have a data connector (Windows Firewall) connected to my workspace. It shows connected and is configured properly. I originally did have the Windows Firewall Events via AMA connector and I set up a DCR for it, but the data connector is showing disconnected now.

Is there something I'm missing to get the FW logs to show in my workspace?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,242 questions
{count} votes

1 answer

Sort by: Most helpful
  1. F S 0 Reputation points
    2025-03-12T17:11:29.2833333+00:00

    It stopped working without me doing anything. I just checked again this morning and now the Windows Firewall data connector is also disconnected. A week ago I originally installed 3 data connectors (Windows Firewall, Windows Firewall via AMA, and Windows Security Events via AMA) and it looks like only the Windows Security Events via AMA is still there. Maybe I should start troubleshooting from here first?BTW forgot to mention that everything is all new to me, so I could definitely be setting things up wrong.

    Also, how do I check DCR settings on my machine?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.