A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Sentinel: Creating Alerts for Windows Update Compliance in GCC Environment — No Data Ingestion
Problem description
I am trying to create an alert in Microsoft Sentinel for Windows Update compliance below 90%, but no data is being ingested into Sentinel despite enabling Windows Update for Business reports over a week ago.
Environment
Microsoft Sentinel in a GCC cloud environment, with Windows Update for Business reports / Update Compliance as the data source.
What I've already tried
I have enabled Windows Update for Business reports in my Log Analytics workspace and waited over a week, but no ingested data appears in Sentinel. I reviewed support documentation and the initial support reply indicated 'No data found.' The case history shows no additional diagnostic output or troubleshooting steps taken by support.
Current status
Currently, I am seeking guidance on whether Windows Update for Business reports can support data ingestion in a GCC environment for compliance alerts, and what alternative supported options exist for monitoring Windows Update compliance in my environment.