Forum Discussion

AndrewX's avatar
AndrewX
Iron Contributor
Jun 01, 2019
Solved

WEF forwarding to Azure Security Centre / Log Analytics

Hello - I am hoping this is possible and a viable option.   I currently use Windows Event Forwarding (WEF) with Winlogbeat sending events off to Elasticsearch. Epic, this works great, why would i...
  • Ofer_Shezaf's avatar
    Jun 16, 2019

    AndrewX 

     

    WEF support is currently in preview and still has some limitations. Contact me directly if you would like to join, and we can discuss whether the current support would work for you.

     

    As an alternative, you can continue to use CEF and winlogbeat and connect it to Sentinel using Logstash and the Logstash Log Analytics output plugin.

     

    ~ Ofer

Resources