Forum Discussion

ujjawalm's avatar
ujjawalm
Copper Contributor
Jun 30, 2020
Solved

Analysis of host data detected a large number of system log files being removed

Analysis of host data detected a large number of system log files being removed, Suspicious Command Line : rm -f /var/log/sa/sa18 We are receiving these alerts in Azure Security Center, and post check...
  • tal_rosler's avatar
    Jul 05, 2020

    Hi ujjawalm ,

    Those alerts are result of a known temporal error in our system caused Azure Security Center to trigger alerts that shouldn't be triggered. The issue was mitigated successfully - you shouldn’t get such alerts anymore. I am very sorry for the inconvenient it caused – please feel free to ignore those alerts.

     

    Thanks,

     

    Tal Rosler,

    Product Manager, Azure Security Center.

Resources