Skip to content

Sentinel DCR emitter

The Sentinel DCR emitter sends normalized events to an Azure Monitor Logs ingestion endpoint using a Data Collection Rule. It batches events by byte size and flush interval, sends each batch as the native JSON array expected by the Logs Ingestion API, optionally compresses requests with gzip, retries transient failures and can write exhausted failures to the DLQ.

Client-secret authentication remains supported for existing deployments:

- name: sentinel-dcr
  type: sentinel_dcr
  batch:
    max_bytes: 1048576
    flush_interval: "5s"
    compression: gzip
  retry:
    max_attempts: 5
    initial_interval: "1s"
    max_interval: "30s"
  dcr:
    logs_ingestion_endpoint: "https://<immutable-id>.<region>-1.ingest.monitor.azure.com"
    rule_id: "<data-collection-rule-id>"
    stream_name: "Custom-Logstrm_CL"
    auth_mode: client_secret
    tenant_id: "${AZURE_TENANT_ID}"
    client_id: "${AZURE_CLIENT_ID}"
    client_secret: "${AZURE_CLIENT_SECRET}"
    scope: "https://monitor.azure.com/.default"

For Azure-hosted deployments, use Managed Identity to avoid a client secret. Omit managed_identity_client_id for a system-assigned identity, or set it to the client ID of a user-assigned identity:

- name: sentinel-dcr
  type: sentinel_dcr
  dcr:
    logs_ingestion_endpoint: "https://<immutable-id>.<region>-1.ingest.monitor.azure.com"
    rule_id: "<data-collection-rule-id>"
    stream_name: "Custom-Logstrm_CL"
    auth_mode: managed_identity
    # Optional; omit for system-assigned identity.
    managed_identity_client_id: "${AZURE_MANAGED_IDENTITY_CLIENT_ID}"
    scope: "https://monitor.azure.com/.default"

For AKS Workload Identity, use auth_mode: workload_identity. The emitter then authenticates as the federated identity behind the pod's service account, using the AZURE_CLIENT_ID, AZURE_TENANT_ID and AZURE_FEDERATED_TOKEN_FILE values injected by the AKS workload identity webhook:

- name: sentinel-dcr
  type: sentinel_dcr
  dcr:
    logs_ingestion_endpoint: "https://<immutable-id>.<region>-1.ingest.monitor.azure.com"
    rule_id: "<data-collection-rule-id>"
    stream_name: "Custom-Logstrm_CL"
    auth_mode: workload_identity
    # Optional; omit to use the AZURE_CLIENT_ID injected by the AKS workload
    # identity webhook. Set it to select a specific federated identity client ID.
    # managed_identity_client_id: "<federated-identity-client-id>"
    # Optional; omit to use AZURE_FEDERATED_TOKEN_FILE from the webhook.
    # federated_token_file: "/var/run/secrets/azure/tokens/azure-identity-token"
    scope: "https://monitor.azure.com/.default"

Wire contract

  • The request path is /dataCollectionRules/<rule_id>/streams/<stream_name> with api-version=2023-01-01.
  • The request body is a JSON array of normalized event objects, not newline-delimited JSON.
  • Set batch.compression: gzip to send a gzip-compressed body with Content-Encoding: gzip. If compression is omitted or set to another value, the body is sent uncompressed.
  • Custom headers are applied after the standard content headers and may override them only when the destination contract requires it.

Production guidance

  • For Managed Identity, assign the identity the Monitoring Metrics Publisher role scoped to the relevant Data Collection Rule, and ensure the hosting platform has that identity attached/enabled. System-assigned identity is selected when managed_identity_client_id is omitted; user-assigned identity is selected by its client ID.
  • For AKS Workload Identity, enable the cluster OIDC issuer and the Workload Identity add-on, create an Entra managed identity with a federated identity credential bound to the Data Plane's Kubernetes service account and namespace, assign it the Monitoring Metrics Publisher role on the Data Collection Rule, and wire the chart with serviceAccount.workloadIdentity.enabled=true (see the Helm guide). Startup validation fails fast when the client ID, tenant ID or federated token file cannot be resolved.
  • auth_mode accepts managed_identity, workload_identity or client_secret. Omitting it preserves the legacy client-secret mode. Managed Identity authentication uses Azure Identity's ManagedIdentityCredential and AKS Workload Identity uses WorkloadIdentityCredential; neither falls back to developer CLI or DefaultAzureCredential chains.
  • Keep client-secret values in a secret manager and never commit them to configuration files.
  • Keep batches below the service and network limits; measure payload size after transformation.
  • Set retry limits according to the destination's outage and recovery characteristics.
  • Enable DLQ and monitor its size before production rollout.

A Sentinel outage should produce explicit emitter errors and DLQ records after retry exhaustion. It should not silently report successful delivery.

Validated deployment

Azure VM Managed Identity

  • Scenario: Logstrm Data Plane on an Azure VM (Ubuntu 22.04 LTS Gen2, x86_64) with a system-assigned identity, sending through sentinel_dcr to a Data Collection Rule and into a custom Log Analytics table.
  • Precondition: the VM identity held the Monitoring Metrics Publisher role scoped to the target Data Collection Rule.
  • Result: a test event injected through a loopback-only test input was accepted by the emitter, delivered through the Azure Monitor Logs Ingestion API and confirmed present in the target Log Analytics table.
  • Scope: validates the ManagedIdentityCredential (IMDS) path for system-assigned identity on Azure VMs. The recorded VM evidence confirms a row arrived, but does not verify preservation of custom event fields. It does not cover user-assigned identity selection or sustained-load throughput.

AKS Workload Identity

A controlled functional smoke test on 2026-09-30 validated auth_mode: workload_identity with the AKS workload identity webhook and a federated Kubernetes service account:

  • One event matching the custom DCR stream schema was sent from the Data Plane pod through the Azure Monitor Logs Ingestion API.
  • The event was confirmed in the target custom Log Analytics table.
  • The Data Plane and Manager deployments became ready, and the Data Plane service remained cluster-internal during the test.
  • The temporary AKS cluster and test identity were removed after evidence collection.

This is a single-event functional validation of the federated identity and DCR delivery path. It is not a throughput, resilience, long-duration or production-readiness assessment. See Helm deployment on Kubernetes for customer setup guidance.