Just to share my recent discoveries for Sentinel and Splunk as well as mentioning Datadog - as I find it noticeable in terms of integrations efforts and pricing.
A publicly available Data Connector can be found on GitHub here. It's just updated to support Azure Functions v4 (as v3 gets deprecated tomorrow).
It's fairly easy to integrate. An important note here: get your Sentinel configured first and find your <Workspace ID> and the <Workspace Key> under Workspace Settings (you don't need to install any agents).
Post deployment you have all your required resources together.
Post integration the Directory Insights logs will be stored in a dedicated table named 'JumpCloud_CL' and the data can be used in Hunting, Workbooks, Incidents etc.
I haven' tried it out, but since 4th October there is a "JumpCloud Directory Insights' add-on available published by Maciej Duda.
This integration exists since a couple of months and was announced here.
I created the Sentinel integration and then deleted it. I later created the Sentinel integration again, but now the Table will not get created. Any idea why the table doesn't get created now? Or how I can create the table?