Forum Discussion
Jeff Walzer
Oct 12, 2021Iron Contributor
MDE for Linux and audit logs
Just confirming that MDE for Linux will ingest events from the audit logs based on the following statement from Microsoft's documentation: System events captured by rules added to /etc/audit/rules....
- Oct 12, 2021You are correct. MDE for Linux leverages and configures auditd rules on the device for the purpose of providing EPP & EDR functionality. Thank you!
Daniel Simpson
Microsoft
Oct 12, 2021You are correct. MDE for Linux leverages and configures auditd rules on the device for the purpose of providing EPP & EDR functionality. Thank you!
Jeff Walzer
Oct 13, 2021Iron Contributor
TYVM for the reply