Forum Discussion
luizao_lf
Apr 01, 2021Copper Contributor
Duplication of events before ingesting
Good morning guys.
I'm working on pointing the fw ASA logs to Sentinel.
I realized that many logs are being sent with the same payload and time in 1 minute, reaching the point of some types of logs being sent more than 30 identical events.
My question is, is there any Sentinel mechanism for summarizing events and before ingesting and not inputting duplicate events? I know QRadar does that.
If you have any answers, you are welcome. @
EX: If the client receives a DDoS attack on a device, will Sentinel summarize several logs and ingest only a few or will it ingest all of the logs?
If you have any answers, you are welcome. 🙂 GaryBushey Thijs Lecomte CliveWatson
1 Reply
- Thijs LecomteBronze ContributorHI
By default, Azure Sentinel does not support filtering pre ingestion. You could look into setting up something such as Logstash to filter the logs before they reach Azure Sentinel.
https://docs.microsoft.com/en-us/azure/sentinel/connect-logstash