Monitoring Azure VMWare (AVS)

Silver Contributor

What is the recommended approach for monitoring the new AVS with Azure Security Center?

2 Replies
Anyone?

@Dean Gross you need to follow the Azure baseline for VMware as described in the article Azure security baseline for Azure VMware Solution | Microsoft Docs

Log Analytics agent collects log data from Azure, Azure VMware Solution, and on-premises VMs. The log data is sent to Azure Monitor Logs and stored in a Log Analytics Workspace. Each workspace has its own data repository and configuration to store data. Once the logs are collected, Azure Security Center assesses the vulnerability status of Azure VMware Solution VMs and raises an alert for any critical vulnerability. Once assessed, Azure Security Center forwards the vulnerability status to Azure Sentinel to create an incident and map with other threats. Azure Security Center is connected to Azure Sentinel using Azure Security Center Connector.

Refer this article for step wise details on how and what to integrate azure-docs/azure-security-integration.md at master · MicrosoftDocs/azure-docs (github.com)