Forum Discussion
securityxpert1122
Aug 18, 2023Copper Contributor
Log forwarder sending duplicate logs
I have two log forwarders sending logs to Sentinel. One is logstash and other one is Azure log forwarder I setup on Ubuntu. Since logstash was sending logs to commonsecuritylogs_CL table and those ...
Usama_Saleem
Aug 21, 2023Brass Contributor
Run the following KQL query to get the list of log forwarders (set the timeframe according to you need)
CommonSecurityLog
| distinct DeviceVendor
CommonSecurityLog
| distinct DeviceVendor