Forum Discussion
Arjan Veen, van
Jun 30, 2022Brass Contributor
Log Analytics design - Defender for Cloud and Sentinel
All, When you have Defender for Cloud and Sentinel.....do you still use 2 log analytics workspaces or do you reconfigure the defender for cloud log analytics workspace to ingest the defender for ...
- Sep 26, 2022
Arjan Veen, van one log analytics is good enough to you can forward the ASC(Azure security center/Defender alerts to Sentinel .
Refer the below picture reference to one of the Microsoft source where it shows one log analytics is good enough for both Azure and On-prem
Clive_Watson
Jun 30, 2022Bronze Contributor
They can happily share a workspace. There are lots of options, but typically I see one workspace.
ellyse
Microsoft
Sep 26, 2022Hi Clive, do you know if there's any guidance or steps on how this can be set up?
- Arjan Veen, vanSep 27, 2022Brass ContributorHello,
browse to defender for cloud - Environment settings - Auto provisioning - Extensions -Log Analytics agent/Azure Monitor agent - Edit Auto-provisioning configuration - Workspace selection and select the Sentinel workspace