Forum Discussion
Arjan Veen, van
Jun 30, 2022Brass Contributor
Log Analytics design - Defender for Cloud and Sentinel
All, When you have Defender for Cloud and Sentinel.....do you still use 2 log analytics workspaces or do you reconfigure the defender for cloud log analytics workspace to ingest the defender for ...
- Sep 26, 2022
Arjan Veen, van one log analytics is good enough to you can forward the ASC(Azure security center/Defender alerts to Sentinel .
Refer the below picture reference to one of the Microsoft source where it shows one log analytics is good enough for both Azure and On-prem
ellyse
Microsoft
Sep 26, 2022Hi Clive, do you know if there's any guidance or steps on how this can be set up?
Arjan Veen, van
Sep 27, 2022Brass Contributor
Hello,
browse to defender for cloud - Environment settings - Auto provisioning - Extensions -Log Analytics agent/Azure Monitor agent - Edit Auto-provisioning configuration - Workspace selection and select the Sentinel workspace
browse to defender for cloud - Environment settings - Auto provisioning - Extensions -Log Analytics agent/Azure Monitor agent - Edit Auto-provisioning configuration - Workspace selection and select the Sentinel workspace