Forum Discussion
Sentinel across multi-region/workspaces
- Mar 02, 2020
Jeff Walzer No need to pair them. You can have multiple workspaces and query across them using a single Azure Sentinel console. Here's an example...
union Update, workspace("otherworkspacename").Update, workspace("otherworkspaceID").Update
| where TimeGenerated >= ago(1h)
| where UpdateState == "Needed"
| summarize dcount(Computer) by ClassificationYou can even save a query like this as a Function so you can just use the Function alias to use it.
Question is...why do you think you might need multiple Sentinel workspaces? Best practice is to use a single workspace if possible.
Reasons why you might want to use multiple workspaces:
- Use of multiple Azure tenants
- For compliance and sovereignty reasons
- To reduce networking costs across regions
Reasons to avoid multiple workspaces:
- Separate billing
- Fine grained retention settings
- Fine grained access control
- Legacy architecture
Jeff Walzer No need to pair them. You can have multiple workspaces and query across them using a single Azure Sentinel console. Here's an example...
union Update, workspace("otherworkspacename").Update, workspace("otherworkspaceID").Update
| where TimeGenerated >= ago(1h)
| where UpdateState == "Needed"
| summarize dcount(Computer) by Classification
You can even save a query like this as a Function so you can just use the Function alias to use it.
Question is...why do you think you might need multiple Sentinel workspaces? Best practice is to use a single workspace if possible.
Reasons why you might want to use multiple workspaces:
- Use of multiple Azure tenants
- For compliance and sovereignty reasons
- To reduce networking costs across regions
Reasons to avoid multiple workspaces:
- Separate billing
- Fine grained retention settings
- Fine grained access control
- Legacy architecture
Rod_Trent- thx for the reply and information.
The reason I thought I would need multiple workspaces is because we have resources in different regions. Is it possible to have resources is one region forward metrics/events via the diagnostic and log analytics agent to another region (in my case resources in the Central region forwarding metrics/events to the East region)?
Thx
- Thijs LecomteMar 03, 2020Bronze ContributorThis webinar might interest you also: https://youtu.be/_mm3GNwPBHU
Around 58m they talk about multiple workspaces and your use case- Jeff WalzerMar 03, 2020Iron Contributor
Thijs Lecomte- TYVM for the link - greatly appreciated
- Rod_TrentMar 03, 2020
Microsoft
Jeff Walzer Yes, absolutely. Azure Sentinel becomes the single pane of glass for your entire infrastructure.