Forum Discussion

fishermc's avatar
fishermc
Copper Contributor
Apr 15, 2021
Solved

Server core event logs

I have been using the Log Analytics agent to get on-premise server event logs into Sentinel and all has gone well with the exception for Server core boxes. Server Core isn't listed as supported (

https://docs.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview#log-analytics-agent) so was wondering what is the best way to get server core logs over into Sentinel.

  • You will need WEF/WEC but support for that will be added in a future release of the Azure Monitor Agent.

Resources