Sentinel DCR emitter¶
The Sentinel DCR emitter sends normalized events to an Azure Monitor Logs ingestion endpoint using a Data Collection Rule. It batches events by byte size and flush interval, sends each batch as the native JSON array expected by the Logs Ingestion API, optionally compresses requests with gzip, retries transient failures and can write exhausted failures to the DLQ.
Client-secret authentication remains supported for existing deployments:
- name: sentinel-dcr
type: sentinel_dcr
batch:
max_bytes: 1048576
flush_interval: "5s"
compression: gzip
retry:
max_attempts: 5
initial_interval: "1s"
max_interval: "30s"
dcr:
logs_ingestion_endpoint: "https://<immutable-id>.<region>-1.ingest.monitor.azure.com"
rule_id: "<data-collection-rule-id>"
stream_name: "Custom-Logstrm_CL"
auth_mode: client_secret
tenant_id: "${AZURE_TENANT_ID}"
client_id: "${AZURE_CLIENT_ID}"
client_secret: "${AZURE_CLIENT_SECRET}"
scope: "https://monitor.azure.com/.default"
For Azure-hosted deployments, use Managed Identity to avoid a client secret. Omit managed_identity_client_id for a system-assigned identity, or set it to the client ID of a user-assigned identity:
- name: sentinel-dcr
type: sentinel_dcr
dcr:
logs_ingestion_endpoint: "https://<immutable-id>.<region>-1.ingest.monitor.azure.com"
rule_id: "<data-collection-rule-id>"
stream_name: "Custom-Logstrm_CL"
auth_mode: managed_identity
# Optional; omit for system-assigned identity.
managed_identity_client_id: "${AZURE_MANAGED_IDENTITY_CLIENT_ID}"
scope: "https://monitor.azure.com/.default"
For AKS Workload Identity, use auth_mode: workload_identity. The emitter then authenticates as the federated identity behind the pod's service account, using the AZURE_CLIENT_ID, AZURE_TENANT_ID and AZURE_FEDERATED_TOKEN_FILE values injected by the AKS workload identity webhook:
- name: sentinel-dcr
type: sentinel_dcr
dcr:
logs_ingestion_endpoint: "https://<immutable-id>.<region>-1.ingest.monitor.azure.com"
rule_id: "<data-collection-rule-id>"
stream_name: "Custom-Logstrm_CL"
auth_mode: workload_identity
# Optional; omit to use the AZURE_CLIENT_ID injected by the AKS workload
# identity webhook. Set it to select a specific federated identity client ID.
# managed_identity_client_id: "<federated-identity-client-id>"
# Optional; omit to use AZURE_FEDERATED_TOKEN_FILE from the webhook.
# federated_token_file: "/var/run/secrets/azure/tokens/azure-identity-token"
scope: "https://monitor.azure.com/.default"
Wire contract¶
- The request path is
/dataCollectionRules/<rule_id>/streams/<stream_name>withapi-version=2023-01-01. - The request body is a JSON array of normalized event objects, not newline-delimited JSON.
- Set
batch.compression: gzipto send a gzip-compressed body withContent-Encoding: gzip. If compression is omitted or set to another value, the body is sent uncompressed. - Custom
headersare applied after the standard content headers and may override them only when the destination contract requires it.
Production guidance¶
- For Managed Identity, assign the identity the
Monitoring Metrics Publisherrole scoped to the relevant Data Collection Rule, and ensure the hosting platform has that identity attached/enabled. System-assigned identity is selected whenmanaged_identity_client_idis omitted; user-assigned identity is selected by its client ID. - For AKS Workload Identity, enable the cluster OIDC issuer and the Workload Identity add-on, create an Entra managed identity with a federated identity credential bound to the Data Plane's Kubernetes service account and namespace, assign it the
Monitoring Metrics Publisherrole on the Data Collection Rule, and wire the chart withserviceAccount.workloadIdentity.enabled=true(see the Helm guide). Startup validation fails fast when the client ID, tenant ID or federated token file cannot be resolved. auth_modeacceptsmanaged_identity,workload_identityorclient_secret. Omitting it preserves the legacy client-secret mode. Managed Identity authentication uses Azure Identity'sManagedIdentityCredentialand AKS Workload Identity usesWorkloadIdentityCredential; neither falls back to developer CLI orDefaultAzureCredentialchains.- Keep client-secret values in a secret manager and never commit them to configuration files.
- Keep batches below the service and network limits; measure payload size after transformation.
- Set retry limits according to the destination's outage and recovery characteristics.
- Enable DLQ and monitor its size before production rollout.
A Sentinel outage should produce explicit emitter errors and DLQ records after retry exhaustion. It should not silently report successful delivery.
Validated deployment¶
Azure VM Managed Identity¶
- Scenario: Logstrm Data Plane on an Azure VM (Ubuntu 22.04 LTS Gen2, x86_64) with a system-assigned identity, sending through
sentinel_dcrto a Data Collection Rule and into a custom Log Analytics table. - Precondition: the VM identity held the
Monitoring Metrics Publisherrole scoped to the target Data Collection Rule. - Result: a test event injected through a loopback-only test input was accepted by the emitter, delivered through the Azure Monitor Logs Ingestion API and confirmed present in the target Log Analytics table.
- Scope: validates the
ManagedIdentityCredential(IMDS) path for system-assigned identity on Azure VMs. The recorded VM evidence confirms a row arrived, but does not verify preservation of custom event fields. It does not cover user-assigned identity selection or sustained-load throughput.
AKS Workload Identity¶
A controlled functional smoke test on 2026-09-30 validated auth_mode: workload_identity with the AKS workload identity webhook and a federated Kubernetes service account:
- One event matching the custom DCR stream schema was sent from the Data Plane pod through the Azure Monitor Logs Ingestion API.
- The event was confirmed in the target custom Log Analytics table.
- The Data Plane and Manager deployments became ready, and the Data Plane service remained cluster-internal during the test.
- The temporary AKS cluster and test identity were removed after evidence collection.
This is a single-event functional validation of the federated identity and DCR delivery path. It is not a throughput, resilience, long-duration or production-readiness assessment. See Helm deployment on Kubernetes for customer setup guidance.