aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Microsoft Sentinel OTLP Capture Guide For Unified aiFObserve

Best Capture Source

Export normalized security events from Microsoft Sentinel or from the OpenTelemetry Collector pipeline that receives Sentinel events. Preserve table name, workspace, subscription, resource, and original event fields.

Basic Logging

Extended Logging

User And App Identity

OTLP Mapping Notes

Put Sentinel-specific values in OTLP attributes. Keep Timestamp, ObservedTimestamp, SeverityText, SeverityNumber, Body, Resource, and Attributes intact so the converter can map both standard and vendor fields.

Source