Forum Discussion
WEF forwarding to Azure Security Centre / Log Analytics
- Jun 16, 2019
WEF support is currently in preview and still has some limitations. Contact me directly if you would like to join, and we can discuss whether the current support would work for you.
As an alternative, you can continue to use CEF and winlogbeat and connect it to Sentinel using Logstash and the Logstash Log Analytics output plugin.
~ Ofer
Hi Ofer_Shezaf what is a current status of it?
AdamPRD : We have decided to move a head with the Azure Monitor Agent (AMA) version, and the current Log Analytics Agent (MMA) version will not become public.
- AndrewXJun 01, 2021Iron ContributorHi,
Twas Jun 01 2019, when i first asked the question, how are we going MS with the WEF support for AMA? - Ofer_ShezafFeb 01, 2021
Microsoft
I am not sure about the compete plans for the AMA. I focus on the Security use cases. Specifically for WEF, yet, as stated above, it would be supported by the AMA. - NW-SSPFeb 01, 2021Copper Contributor
Ofer_Shezaf the AMA is supposed to replace your 3 current agents, right? Reading security events is also a functionality of the new product. Can we expect the desired functionality: Forwarding events to LAW/Sentinel that are stored under 'ForwardedEvents' with the AMA?