Forum Discussion

Victor1989's avatar
Victor1989
Copper Contributor
Nov 07, 2022

How to view security event logs for AMA agents for windows.

there is nothing coming up in sentinel with query SecurityEvent.

AMA connector says "Disconnected" however i created DCR from log analytic workspace => Agent management.( all are azure virtual machines ) so i believe ARC is not required.

 

Connector "Security Events via Legacy Agent" shows connected automatically , not the "Windows Security Events via AMA"

 

Rod_Trent 

    • Victor1989's avatar
      Victor1989
      Copper Contributor
      i have created DCR rules through Log Analytic workspaces==> agent management
      • Clive_Watson's avatar
        Clive_Watson
        Bronze Contributor

        Victor1989 Is the DCR listed, I don't have any but if I did, they would be below?  If they are not here then we know Sentinel is unable to see them, may they're aligned to another workspace or RG?

         

Resources