Forum Discussion
Integration of Sentinel with other 3rd party on-prem SIEM solutions (stream alerts to eventhub)
- Apr 07, 2019
Hi Manuel_DEste, great meeting you again!
Yes and no.
Forwarding alerts to an event hub is supported. You can use one of several ways:
- Run a Logic App scheduled playbook to read alerts using the Log Analytics connector and then write them to an event hub using the Event Hub connector.
- Soon you will be able to do it by running a playbook automatically when an alert triggers.
- Lastly, you can Use the Security Graph API. Note that this will send all Azure alerts to your SIEM, not just Sentinel's.
Why no? because what you really want to send are cases and not alerts, which are automatically aggregated and reduced alerts. We are working to make sure those can be sent to a SIEM as well.
Ofer_Shezaf hey i have one question: i am new in azure sentinel, and i want to know what is the difference between using MMA agent and Using syslogs in adding 3d party ressource
thank you
BMaro Syslog is used for remote collection for systems that support it (which is most networking and security systems). The MMA (or Log Analytics Agent), is our software for collecting both Syslog as well as local telemetry on the system the MMA is installed on.