# Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines

DevFeed: [Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines](<https://devfeed.tech/articles/transform-and-route-security-logs-to-microsoft-sentinel-tables-using-observability-pipelines-31547.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/observability-pipelines-microsoft-sentinel-packs/>)

Author: Zara Boddula; Danielle Park

Published: 2026-09-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [cisco-meraki](<https://devfeed.tech/tags/cisco-meraki.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fortigate](<https://devfeed.tech/tags/fortigate.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

## AI overview

Datadog's Observability Pipelines Packs transform firewall, VPN, and network detection logs into Microsoft Sentinel table schemas before ingestion. The post describes Packs for Palo Alto Networks, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop, including filtering and noise reduction to help control Sentinel ingest volume while retaining visibility.

## Source excerpt

Learn how Observability Pipelines Packs map security logs to Microsoft Sentinel schemas and help control downstream ingest volume.