Forum Discussion

jt-jt's avatar
jt-jt
Copper Contributor
Mar 04, 2022

log via syslog server agent to Azure Sentinel (list of IPs?) & dual agent to two Log Analytics space

Hi,

I am currently looking at setting up something like this:

Security devices > syslog server > Microsoft Sentinel

In order to tie down/restrict somewhat the access this syslog server has, is there a list of known IPs for Microsoft Sentinel?

 

Another bonus question please πŸ˜„

For one of the firewalls (one of the security devices mentioned above) we are looking to send a full set to Sentinel via this syslog server, PLUS a smaller subset of the SAME log (but with only selected columns/fields) to another Log Analytics workspace. This might be outside of scope of the syslog server agent but is there a guide on how to get this setup please?

 

Many thanks.

JT

2 Replies

Resources