By Rod Trent and Azure Sentinel News
If you want to have the information from the Microsoft AlwaysOn VPN in Azure Sentinel, do the following:
 Make sure you have the Azure Monitor Agent (MMA, Log Analytics Agent) installed and are collecting the Application log.
Add the Application log to the Agent Configuration in the Log Analytics Workspace for Azure Sentinel
 Query for “RasClient” in the Event table.
Event | where Source == "RasClient"
Look for the RenderedDescription data column for goodness
In the Event table for RasClient there’s also a RenderedDescription data column that can be parsed. It contains things like:
- Tunnel IP address
- User name
- Media type
- Termination code
- And lots more…
Lots of goodness here. Have fun!
Common error codes are shown here: Troubleshoot Always On VPN | Microsoft Docs