Forum Discussion

Magnus Tjerneld's avatar
Magnus Tjerneld
Brass Contributor
May 04, 2020
Solved

"Azure Monitor for VMs" causing huge data volumes in Sentinel

Hi! We enabled Azure Monitor for VMs for our on premise servers a few weeks ago, and we are very happy with the service so far. The problem is that we have Azure Sentinel connected to our Log Anal...
  • hspinto's avatar
    hspinto
    May 08, 2020

    Magnus Tjerneld 

     

    There isn't currently a way of filtering out what should not be processed by Sentinel. For this reason, you should probably consider using different workspaces for Azure Monitor for VMs and Sentinel.

     

    If you are collecting other data from your VMs besides Performance metrics that you consider useful for Sentinel (e.g., Azure Security Center Standard security events, other system events, custom logs, etc.), then you will need to implement multi-homing (i.e., the same Log Analytics agent sending different data with different purposes to different workspaces). This is however not supported yet for Linux machines. 

     

    I recommend you to read this nice article about Sentinel/ASC workspace design, as it might give some more insights: https://techcommunity.microsoft.com/t5/azure-sentinel/best-practices-for-designing-an-azure-sentinel-or-azure-security/ba-p/832574

Resources