Home

Ingesting Windows Radius Server logs into Azure Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-735213%22%20slang%3D%22en-US%22%3EIngesting%20Windows%20Radius%20Server%20logs%20into%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-735213%22%20slang%3D%22en-US%22%3E%3CP%3EDoes%20anyone%20have%20any%20experience%20%2F%20knowledge%20in%20getting%20Windows%20Server%202012%20R2%20Radius%20Server%20logs%2C%20being%20written%20in%20ODBC%20format%20as%20text%20files%2C%20into%20Azure%20Sentinel.%20The%20online%20info%20seems%20to%20be%20almost%20non%20existent%20(%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-736702%22%20slang%3D%22en-US%22%3ERe%3A%20Ingesting%20Windows%20Radius%20Server%20logs%20into%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-736702%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F312381%22%20target%3D%22_blank%22%3E%40PeterJ_Inobits%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFrom%20memory%2C%20Radius%20logs%20write%20to%20a%20file%20you%20name.%26nbsp%3B%20You%20can%20then%20use%20Log%20Analytics%20to%20import%20the%20file%20as%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-custom-logs%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ecustom%20log%3C%2FA%3E%20-%20I%20haven't%20tried%20it%20though%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20they%20can%20be%20written%20to%20a%20EventLog%2C%20then%20you%20can%20just%20add%20that%20log%20again%20via%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-windows-events%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20Log%20Analytics%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
PeterJ_Inobits
New Contributor

Does anyone have any experience / knowledge in getting Windows Server 2012 R2 Radius Server logs, being written in ODBC format as text files, into Azure Sentinel. The online info seems to be almost non existent (  

1 Reply

@PeterJ_Inobits 

 

From memory, Radius logs write to a file you name.  You can then use Log Analytics to import the file as a custom log - I haven't tried it though?

 

If they can be written to a EventLog, then you can just add that log again via Log Analytics 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies