SFTP To Go: Managed SFTP Cloud Storage as a Service SFTP To Go
Microsoft Sentinel
Microsoft Sentinel

Microsoft Sentinel

SIEM Solutions

SFTP To Go

SFTP To Go is a fully managed secure, scalable, and reliable cloud file storage service supporting SFTP, FTPS, S3, and HTTPS protocols. It allows sharing and integration with third parties using popular and secure protocols, and automates data management and processing using APIs and webhooks.

  • Secure data transfer and transparent encryption at rest
  • Reliable offsite backup
  • Compatibility and ease of use

Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM and security orchestration platform that uses Log Analytics workspaces, KQL queries, analytics rules, incidents, and workbooks to help security teams collect, investigate, and respond to security events. By connecting SFTP To Go with Microsoft Sentinel, you can stream SFTP To Go audit log events to a Log Analytics custom table, then use those events for SFTP activity search, analytics rules, alerts, investigations, and security reporting.

  • Stream SFTP To Go audit log events to a Microsoft Sentinel-enabled Log Analytics workspace
  • Search and filter SFTP activity by event type, organization, user, IP address, timestamp, and file activity
  • Use SFTP audit events in KQL queries, analytics rules, alerts, incidents, investigations, and workbooks

How does it work?

  1. In Azure, confirm that Microsoft Sentinel is enabled on the Log Analytics workspace that should receive SFTP To Go audit log events. SFTP To Go’s Microsoft Sentinel destination currently supports Azure public cloud only.
  2. In SFTP To Go, add Microsoft Sentinel as a streaming audit log destination by following the SFTP To Go documentation for Microsoft Sentinel destinations. Complete the Azure resource setup and SFTP To Go destination setup there before continuing with the Sentinel search, analytics, alerting, and workbook steps below.
  3. After the destination is saved in SFTP To Go, generate a test event by performing an auditable action, such as a login, failed login, upload, download, delete, or access-denied attempt.
  4. In Microsoft Sentinel or Log Analytics, open Logs and query the custom table created for SFTP To Go audit events. Start with the table name you configured, such as SftptogoAuditLog_CL, then narrow the query by time range.
  5. Confirm that the test event arrives with the expected top-level fields. SFTP To Go sends TimeGenerated, Source, Service, EventType, OrganizationId, and Data. The Data column carries the SFTP To Go audit log object.
  6. Use KQL to check the most important SFTP To Go security events. Useful starting filters include Source == "sftptogo", Service == "audit-logs", and EventType == "user.login-failed", EventType == "user.access-denied", or EventType == "file.downloaded".
  7. Inspect the nested Data object and identify the fields your team will use most often during investigations. Common fields include username, principal type, session ID, IP address, location, user agent, file path, timestamp, and event-specific data.
  8. Create saved KQL queries for common SFTP To Go investigations. For example, create queries for failed logins, access-denied events, file deletes, high-volume downloads, unusual IP addresses, activity by user, and activity by organization.
  9. Create scheduled analytics rules for high-priority SFTP To Go security events. Useful starting points include repeated failed logins, explicit access-denied events, unexpected delete activity, downloads from unfamiliar locations, or unusual spikes in file activity.
  10. Configure entity mapping where the available fields support it. For example, map account, IP address, host, or URL-style fields where your SFTP To Go audit data and Sentinel rule design provide suitable values.
  11. Review generated alerts and incidents in Microsoft Sentinel when an analytics rule matches. Use the matched SFTP To Go logs, event type, user details, source IP address, file path, and activity data to support triage and investigation.
  12. Build Microsoft Sentinel workbooks or saved views for recurring SFTP To Go monitoring. For example, create views for recent failed logins, access-denied events, file deletes, high-volume downloads, activity by user, activity by IP address, and file activity over time.
  13. If your Sentinel environment uses ingestion-time transformations, review whether the SFTP To Go custom table should keep the default structure or apply additional parsing, enrichment, filtering, or normalization through the associated data collection rule.
  14. Test the complete workflow by triggering each important event type in SFTP To Go and confirming that it appears in the custom table with the expected timestamp, event type, organization ID, nested data object, KQL query results, analytics rules, alerts, incidents, and workbooks.
  15. Monitor delivery health in SFTP To Go and ingestion behavior in Azure. If events stop arriving, check the SFTP To Go destination status, Entra app credentials, client secret validity, role assignment, data collection endpoint URL, DCR immutable ID, stream name, custom table schema, and any DCR transformation that could prevent expected events from landing in the table.
  16. As your security monitoring requirements change, update your custom table handling, KQL queries, analytics rules, entity mapping, automation, incidents, and workbooks without changing the underlying SFTP To Go file transfer environment.

You can find further insight here, here, here, here, and here.

Ready to get started?

Be up and running with your secure cloud storage in seconds

Get started with a free trial
You’ve successfully subscribed to SFTP To Go: Managed SFTP Cloud Storage as a Service
Welcome back! You’ve successfully signed in.
Great! You’ve successfully signed up.
Success! Your email is updated.
Your link has expired
Success! Check your email for magic link to sign-in.
Please enter at least 3 characters 0 Results for your search