Forum Discussion

kausiktsi's avatar
kausiktsi
Copper Contributor
Feb 18, 2021

Azure Sentinel for On premises without MMA agent

Hi

I have a use case where customer don't want to install any MMA agent on their machines/NEs to collect the data due to some security reason so how do we address such situation and what is the work around?

my understanding i should go for syslog forwarded/CEF to collect the on premises logs from different sources and send it to Azure sentinel over 443 or via private connect. could any one can suggest if this will work or any workable solution. Thanks a lot

Resources