POWERSHELL COMMAND
Set-XdrSentinelConnection
Configures the Sentinel (Log Analytics) workspace connection for data export.
Stores the Log Analytics workspace ID and shared key in script-scoped variables used by Export-XdrToSentinel and Invoke-XdrDefenderHarvest.
The shared key can be found in the Azure portal under: Log Analytics workspace > Agents > Log Analytics agent instructions > Primary/Secondary key
Syntax
Set-XdrSentinelConnection [-WorkspaceId] <string> [-SharedKey] <string> [[-DceEndpoint] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-WorkspaceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The Log Analytics workspace ID (GUID).
-SharedKey
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The primary or secondary shared key for the workspace.
-DceEndpoint
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Not documented |
Optional Data Collection Endpoint URI. When set, uses the DCR/DCE ingestion API instead of the legacy HTTP Data Collector API. Not required for most use cases.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the command runs without updating the module’s Sentinel connection settings.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before updating the module’s Sentinel connection settings.
Examples
Set-XdrSentinelConnection -WorkspaceId "12345678-abcd-1234-abcd-123456789012" -SharedKey "base64key=="
$key = Read-Host -AsSecureString "Shared Key"
Set-XdrSentinelConnection -WorkspaceId "12345678-abcd-1234-abcd-123456789012" -SharedKey ([System.Net.NetworkCredential]::new('', $key).Password)