A New Version of the Windows Security Events Connector?
According to Microsoft docs, the new Windows Security Events connector lets you stream security events from any Windows server (physical or virtual, on-premises or in any cloud) connected to your Azure Sentinel workspace. There are now two versions of this connector:
Security events (legacy version): Based on the Log Analytics Agent (Usually known as the Microsoft Monitoring Agent (MMA) or Operations Management Suite (OMS) agent).
Windows Security Events (new version): Based on the new Azure Monitor Agent (AMA).
Other Windows Event Providers
We also need to use DCRs to handle the collection of events from other Windows event providers besides Microsoft-Windows-Security-Auditing
A New Version of the Windows Security Events Connector?
According to Microsoft docs, the new Windows Security Events connector lets you stream security events from any Windows server (physical or virtual, on-premises or in any cloud) connected to your Azure Sentinel workspace. There are now two versions of this connector:
Other Windows Event Providers
We also need to use DCRs to handle the collection of events from other Windows event providers besides
Microsoft-Windows-Security-Auditing
References: