Azure Sentinel: Collecting logs from Microsoft Services and Applications


Azure Sentinel supports collecting telemetry from a wide array of Microsoft sources. Some of them are listed in the Sentinel’s connector page and documentation. However, Sentinel can collect logs from most Azure services, even when not listed above. 


 


To log a service to Sentinel, pick the service (1), select “Activity log” from the menu (2), and then click the “Logs” button (3). Note that in this screen, before pressing “Logs” you can review the information that will be sent to Sentinel.


 



2019-08-07 12_04_38-Clipboard.png


 



On the next screen, click “Add”, then “Select workspace” and select the Sentinel workspace.


 


In some cases, the service provides diagnostic telemetry but not audit logs. The diagnostic telemetry is usually geared towards operations rather than security monitoring but in most cases will be useful also for security monitoring. In such cases use “Diagnostic settings” instead of “Activity log” and select “Add diagnostic setting”.


 


You can find detailed further instructions for some services here. Note that some of them do not use the method outlined above:



Leave a Reply

Your email address will not be published. Required fields are marked *

*

This site uses Akismet to reduce spam. Learn how your comment data is processed.