Export normalized security events from Microsoft Sentinel or from the OpenTelemetry Collector pipeline that receives Sentinel events. Preserve table name, workspace, subscription, resource, and original event fields.
Put Sentinel-specific values in OTLP attributes. Keep Timestamp, ObservedTimestamp, SeverityText, SeverityNumber, Body, Resource, and Attributes intact so the converter can map both standard and vendor fields.