Forum Discussion
bluelogik
May 18, 2020Copper Contributor
Azure Sentinel integrate with Linux logs
Hello everyone,
I would like to see if there is a way to query "Event Log Cleared" on Linux system(s), in particular, what the events look like when/after being cleared? For example, for Windows, its EventID 1102, so I am curious to find out if there is something similar for Linux systems.
Thank you!
3 Replies
- Ofer_Shezaf
Microsoft
- bluelogikCopper Contributor
Ofer_Shezaf thank you!
- bluelogik : Were you able to develop any similar template for linux ?