Microsoft Sentinel receives the Authdog audit stream through the Azure Log Analytics Data Collector API. Lidar still detects and triages inside Authdog. This channel copies the same events into a custom table in the workspace you already investigate. Configuration belongs to one environment.

## Create the channel

In the [Authdog console](https://console.authdog.com):

1. Select the project and environment.
2. Open **Notifications > Channels**.
3. Select **Add Channel**.
4. Set **Channel Name** and **Channel Type** to **Microsoft Sentinel**.
5. Paste the **Workspace ID**. It is the Log Analytics workspace GUID from **Workspace settings > Agents**.
6. Paste the **Shared Key**. Use the workspace primary or secondary key.
7. Optionally set **Custom Log Table**. The default is `AuthdogAudit`. The name is alphanumeric. Azure stores the records as `<name>_CL`, so the default table is `AuthdogAudit_CL`.
8. Choose the event triggers. Leave the event list empty to drain every event. Build a narrower list from the [event catalog](/docs/events-webhooks).
9. Save, then send a test delivery.

The shared key is stored as a secret. Later edits show it as redacted. Select **Change** only when you are replacing it.

## What lands in Sentinel

Deliveries use the workspace key, not the `X-Authdog-Signature` header used by generic webhooks. A `2xx` from Log Analytics is success. Failures retry with exponential backoff, starting at 60 seconds, for at most five attempts. Redelivery signs the stored payload again with the current shared key. Inspect delivery records if a test does not appear.

The custom table can take a few minutes to show the first rows. Search `_CL` after that, not the bare name you typed.

This is log intake, not a Lidar detector. Signals stay in the console under **Lidar**.

## Test it

1. Trigger a sign-in in the same environment.
2. In the Log Analytics workspace, query the `_CL` table once it exists.
3. Confirm a failed destination shows up in delivery records, then recovers after Azure accepts the retry.

Repeat the channel in production with a production workspace. Channels do not copy between environments.

## Related

| Read | To learn how to |
| --- | --- |
| [Events and webhooks](/docs/events-webhooks) | Channel fields, retries, and the event catalog |
| [Datadog](/marketplace/datadog/setup) | The same stream, sent to Datadog |
| [Marketplace](/marketplace/sentinel) | The listing for this integration |
