Forum Discussion
George Smyrlis
Microsoft
Dec 06, 2019SIEM integration missing from Azure ATP portal?
Hello team!
Could anyone help me with why I cannot find the SIEM integration under Data Sources from the Azure ATP Configuration portal? Although this is fully documented (https://docs.microso...
- Dec 10, 2019
Integrated sensors cannot listen to SIEM (syslog) traffic any more.
They actually don't need too...
They are installed on the DC itself, thus can get all the info they need locally.
EliOfek
Microsoft
Dec 06, 2019Docs is not properly updated, pending a fix.
Standalone sensors are now listening to SIEM events by default. No need to configure them.
Standalone sensors are now listening to SIEM events by default. No need to configure them.
- George SmyrlisDec 10, 2019
Microsoft
Thank you a lot EliOfek for your response. However, I am not using the Standalone Sensor but the Azure ATP Sensor directly installed on every DC. Does the same applies there? Thank you
- EliOfekDec 10, 2019
Microsoft
Integrated sensors cannot listen to SIEM (syslog) traffic any more.
They actually don't need too...
They are installed on the DC itself, thus can get all the info they need locally.