Configure your Log Analytics workspace in Microsoft Azure
To send alerts from Microsoft Sentinel to the QRadar® platform, you must configure your Log Analytics workspace in Microsoft Azure.
Ensure that you have a Log Analytics workspace and permission to modify roles for the workspace. For example, if you have the owner role for the workspace, you have the correct permissions. For more information about creating and configuring a Log Analytics workspace, see the Microsoft Azure Documentation (https://docs.microsoft.com/en-us/azure/azure-monitor/logs/quick-create-workspace?tabs=azure-portal).
After you configure your Log Analytics workspace in Microsoft Azure, add a data source that uses the Universal Cloud REST API connector.
For more information about adding a data source, see Adding ingestion data sources.
For more information about using the Universal Cloud REST API connector when you configure the data source, see Universal Cloud REST API data source parameters for Microsoft Sentinel.