Azure Security Monitoring

Hello everyone,

I am new to Azure and currently doing security monitoring in azure security center. I have few questions that i would like to ask.

Currently there are syslogs coming in from machines and i am to create rules to fire an alert if it detects security events. so my questions are:

1. does azure come with pre defined default rule? if yes where are they and how can i enable/disable them.


Hi Shiva,


There is a new capability in Azure Security Center to turn every log query into security alert. See documentation here: and recorded demo here:


About ingestion of security solutions, we do prefer using CEF over Syslog rather than simple Syslog though both are possible. CEF provides more structured format and indexing. See more details on CEF support here:


Hope it helps,

            Meir :>