Forum Discussion
unixdespair
Mar 01, 2019Copper Contributor
Adding On-Prem Domain Controller Event Logs
We've added several sources (ASA, syslog, multiple Azure sources) .. what is the best way to get our on-prem domain controllers to feed into Sentinel?
endakelly
May 20, 2020Brass Contributor
unixdespair If you've got an Azure Security Centre standard subscription, you can install the Microsoft Monitoring Agent and link it to ASC. This will collect logs from the machine. You can then connect ASC to Sentinel.