Forum Discussion
bluelogik
May 18, 2020Copper Contributor
Azure Sentinel integrate with Linux logs
Hello everyone,
I would like to see if there is a way to query "Event Log Cleared" on Linux system(s), in particular, what the events look like when/after being cleared? For example, for Windows, its EventID 1102, so I am curious to find out if there is something similar for Linux systems.
Thank you!
- Ofer_ShezafMicrosoft
- bluelogikCopper Contributor
Ofer_Shezaf thank you!
- Consultant1520Copper Contributorbluelogik : Were you able to develop any similar template for linux ?