SecurityEvent logs not ingesting into Sentinel

Norah 20 Reputation points
2025-10-15T09:31:44.71+00:00

SecurityEvent logs are not getting ingested into Sentinel, but heartbeat and ASimDNS logs are coming from the same server. Logging is happening on the servers Event viewer.

The log ingestion starts again automatically after a few days. Could you please help us check this issue? Also, please share any documentation on how to review AMA logs for troubleshooting.

Microsoft Security | Microsoft Sentinel

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.