Forum Discussion
Mike82
Aug 11, 2021Copper Contributor
Sysmon log collection via Azure monitor agent (AMA)
Hi Team I have a quick question regarding Azure monitoring agent. I want to capture Sysmon logs from a Azure machine which has AMA extension installed and data collection rule set to all events....
- Oct 12, 2022Updated blog post on this topic: https://jeffreyappel.nl/deploy-sysmon-and-collect-data-with-sentinel-and-the-ama-agent/
Mike82
Sep 30, 2022Copper Contributor
A workaround to get the logs is to add - "Windows event log" configuration under the "Legacy agents managment" section of LA workspace. Check the screenshot below :
I am sure there are better ways via DCR to do this. 🙂
Clive_Watson
Oct 12, 2022Bronze Contributor
Updated blog post on this topic: https://jeffreyappel.nl/deploy-sysmon-and-collect-data-with-sentinel-and-the-ama-agent/
- Mike82Oct 13, 2022Copper ContributorGreat thanks for sharing 🙂