Have you noticed empty fields in the Common Security Event Format (CEF) logs when collecting them in Microsoft Sentinel?
After setting up log forwarding to syslog servers and once the logs start flowing into Sentinel, it's common to see entries with many...