Forum Discussion

cklonger's avatar
cklonger
Copper Contributor
Dec 04, 2020

Multiple Log analytic workspace and rules

Good morning:

 

I am a newbie of Azure Sentinel.

Our env has setup multiple subscriptions and Log analytic workspaces for different productions.

 I would like to trigger some rules (from template) in Log analytic workspaces to monitor all our productions. Should I setup rules in every Log analytic workspace or only one of them ? To view all incidents in one workbook, should I forward the logs from different resources (different subscriptions) to one special Log analytic workspaces?

 

Resources