Forum Discussion
Mike82
Aug 11, 2021Copper Contributor
Sysmon log collection via Azure monitor agent (AMA)
Hi Team I have a quick question regarding Azure monitoring agent. I want to capture Sysmon logs from a Azure machine which has AMA extension installed and data collection rule set to all events....
- Oct 12, 2022Updated blog post on this topic: https://jeffreyappel.nl/deploy-sysmon-and-collect-data-with-sentinel-and-the-ama-agent/
KenzProfile
Microsoft
Aug 17, 2022Same question. Next year. It looks like you would have to configure some type of data collection rule (DCR) using xpath. Or some other coding. Has anybody done this? And yes, it appears far more complex with the AMA. Thanks, and I hope I am wrong.
- Mike82Sep 30, 2022Copper Contributor
A workaround to get the logs is to add - "Windows event log" configuration under the "Legacy agents managment" section of LA workspace. Check the screenshot below :
I am sure there are better ways via DCR to do this. 🙂
- Clive_WatsonOct 12, 2022Bronze ContributorUpdated blog post on this topic: https://jeffreyappel.nl/deploy-sysmon-and-collect-data-with-sentinel-and-the-ama-agent/
- Mike82Oct 13, 2022Copper ContributorGreat thanks for sharing 🙂