Forum Discussion
Arjan Veen, van
Jun 30, 2022Brass Contributor
Log Analytics design - Defender for Cloud and Sentinel
All, When you have Defender for Cloud and Sentinel.....do you still use 2 log analytics workspaces or do you reconfigure the defender for cloud log analytics workspace to ingest the defender for ...
- Sep 26, 2022
Arjan Veen, van one log analytics is good enough to you can forward the ASC(Azure security center/Defender alerts to Sentinel .
Refer the below picture reference to one of the Microsoft source where it shows one log analytics is good enough for both Azure and On-prem
ā
Clive_Watson
Jun 30, 2022Bronze Contributor
They can happily share a workspace. There are lots of options, but typically I see one workspace.
- ellyseSep 26, 2022
Microsoft
Hi Clive, do you know if there's any guidance or steps on how this can be set up?- Arjan Veen, vanSep 27, 2022Brass ContributorHello,
browse to defender for cloud - Environment settings - Auto provisioning - Extensions -Log Analytics agent/Azure Monitor agent - Edit Auto-provisioning configuration - Workspace selection and select the Sentinel workspace- ellyseSep 27, 2022
Microsoft
Hi - I'm not seeing any mention of "Auto - provisioning ..." etc in the MDC environment settings. Could it be somewhere else?