Forum Discussion
PhilippeA
Jul 14, 2020Copper Contributor
Azure ATP syslog events - Firewall settings ???
Hi, what is/are the range(s) to open (on our perimeter firewall) towards our internal syslog proxy (that forwards to the internal SIEM), that is to receive AATP syslog events ?? I didn't find an...
EliOfek
Microsoft
Jul 14, 2020PhilippeA yes, with one correction, the notifications are not sent/pushed, they are pulled by the sensor from the backend (when available) .
PhilippeA
Jul 14, 2020Copper Contributor
OK, that makes more sense now... 😉
(the techs are gonna be happy, they were freaking out... :-))
Any idea whether the 'pull' approach induces any delay, and if yes, how much (+-) ?
And btw, many, many thanks !!!