Forum Discussion
Neil2020
Apr 13, 2020Copper Contributor
Audit-Failed Events not reaching Workspace
I have a test VM in Azure and one running on my home PC, Both have the MMA agent are are sending Security Events to Sentinel's Log Analytics Workspace via ASC connector configuration, Audi-Su...
YanivSh
Microsoft
Apr 13, 2020Neil2020 if the workspace is shared between ASC and sentinel you can configure the log level ( minimal\command\full) only on one side: ASC or sentinel.
https://docs.microsoft.com/en-us/azure/sentinel/connect-windows-security-events
can you please share print screen from the defintion on the security event connector (on sentinel side)
and the ASC workspace setting (under settings).
see relevant pic from sentinel configuration