Home
%3CLINGO-SUB%20id%3D%22lingo-sub-1072510%22%20slang%3D%22en-US%22%3ESearching%20ATP%20for%20Azure%20Storage%20Alerts%20in%20Log%20Analytics%20Workspace%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1072510%22%20slang%3D%22en-US%22%3E%3CP%3EFollowing%20up%20on%20my%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Security-Center%2FValidating-ATP-for-Azure-Storage-Detections-in-Azure-Security%2Fba-p%2F1068131%22%20target%3D%22_self%22%3Eprevious%20post%3C%2FA%3E%20about%20the%20new%20detection%20for%20ATP%20for%20Azure%20Storage%20alerts%2C%20I%20received%20the%20following%20question%3A%20%3CEM%3EI%E2%80%99m%20trying%20to%20find%20the%20alert%20that%20I%20received%20in%20my%20workspace%20and%20my%20search%20results%20comes%20up%20blank.%20Why%3F%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20is%20actually%20expected%20and%20can%20easily%20be%20reproduced%2C%20here%20my%20result%20when%20I%20search%20for%20alerts%20where%20the%20name%20contains%20%E2%80%9Cmalware%E2%80%9D%20(based%20on%20the%20alert%20of%20my%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Security-Center%2FValidating-ATP-for-Azure-Storage-Detections-in-Azure-Security%2Fba-p%2F1068131%22%20target%3D%22_self%22%3Eprevious%20post%3C%2FA%3E).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F162311i20061A996C7A9CD0%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22SearchforMalwareNoResult_2.JPG%22%20title%3D%22SearchforMalwareNoResult_2.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20reason%20for%20that%20is%20because%20not%20all%20security%20alerts%20are%20automatically%20saved%20in%20the%20workspace%2C%20and%20that%E2%80%99s%20why%20at%20Microsoft%20Ignite%20we%20released%20a%20new%20capability%20that%20allows%20you%20to%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fcontinuous-export%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Econtinuously%20export%3C%2FA%3E%20%3CEM%3Eall%20security%20alerts%3C%2FEM%3E%20and%20%3CEM%3Esecurity%20recommendations%3C%2FEM%3E%20to%20the%20Log%20Analytics%20workspace%20used%20by%20Azure%20Security%20Center.%3C%2FP%3E%0A%3CP%3ETo%20use%20this%20feature%2C%20open%20Azure%20Security%20Center%20dashboard%2C%20go%20to%20%3CSTRONG%3EPricing%20and%20Settings%3C%2FSTRONG%3E%2C%20select%20the%20subscription%20that%20you%20want%20to%20export%20data%20from%2C%20click%20%3CSTRONG%3EContinuous%20Export%3C%2FSTRONG%3E%20and%20click%20%3CSTRONG%3ELog%20Analytics%20workspace%3C%2FSTRONG%3E%20tab.%20Select%20the%20options%20as%20shown%20below%20(customize%20the%20settings%20according%20to%20your%20preference)%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F162343iCC416B89443A23F8%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22ExportConfiguration2.JPG%22%20title%3D%22ExportConfiguration2.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAfter%20making%20the%20appropriate%20selections%2C%20click%20%3CSTRONG%3ESave%3C%2FSTRONG%3E.%20Keep%20in%20mind%20that%20if%20you%20are%20ingesting%20Azure%20Security%20Center%20alerts%20in%20Azure%20Sentinel%20using%20the%20ASC%20connector%2C%20you%20will%20receive%20the%20warning%20below%2C%20which%20bring%20awareness%20that%20you%20may%20have%20duplication%20if%20you%20use%20this%20feature%3A%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F162345iD9675424334298E4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Sentinel.JPG%22%20title%3D%22Sentinel.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3ENote%3A%20%3CSPAN%20style%3D%22text-align%3A%20left%3B%20color%3A%20%23333333%3B%20text-transform%3A%20none%3B%20line-height%3A%201.7142%3B%20text-indent%3A%200px%3B%20letter-spacing%3A%20normal%3B%20font-family%3A%20inherit%3B%20font-size%3A%2016px%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20300%3B%20text-decoration%3A%20none%3B%20word-spacing%3A%200px%3B%20display%3A%20inline%20!important%3B%20white-space%3A%20normal%3B%20cursor%3A%20text%3B%20orphans%3A%202%3B%20float%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20background-color%3A%20%23ffffff%3B%22%3Eif%20you%20already%20have%20this%20integration%2C%20than%20the%20ATP%20for%20Azure%20Storage%20alerts%20will%20be%20already%20in%20the%20workspace%20anyway%2C%20therefore%20you%20don't%20need%20to%20export%20the%20alerts%20again.%3C%2FSPAN%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENow%20if%20you%20want%20to%20validate%2C%20repeat%20the%20steps%20from%20my%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Security-Center%2FValidating-ATP-for-Azure-Storage-Detections-in-Azure-Security%2Fba-p%2F1068131%22%20target%3D%22_self%22%3Eprevious%20post%3C%2FA%3E%20to%20simulate%20the%20ATP%20for%20Azure%20Storage%20alert%20again.%20Once%20you%20finish%2C%20you%20can%20search%20for%20the%20alert%20in%20the%20workspace%20and%20you%20will%20see%20that%20it%20is%20there%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F162344i2F7279473D0C7786%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22SearchforMalwareWithResult.JPG%22%20title%3D%22SearchforMalwareWithResult.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20more%20information%20about%20the%20Continue%20Export%20feature%2C%20read%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fcontinuous-export%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1072510%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Security%20Center%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Following up on my previous post about the new detection for ATP for Azure Storage alerts, I received the following question: I’m trying to find the alert that I received in my workspace and my search results comes up blank. Why?

 

This is actually expected and can easily be reproduced, here my result when I search for alerts where the name contains “malware” (based on the alert of my previous post).

 

SearchforMalwareNoResult_2.JPG

 

The reason for that is because not all security alerts are automatically saved in the workspace, and that’s why at Microsoft Ignite we released a new capability that allows you to continuously export all security alerts and security recommendations to the Log Analytics workspace used by Azure Security Center.

To use this feature, open Azure Security Center dashboard, go to Pricing and Settings, select the subscription that you want to export data from, click Continuous Export and click Log Analytics workspace tab. Select the options as shown below (customize the settings according to your preference):

 

ExportConfiguration2.JPG

 

After making the appropriate selections, click Save. Keep in mind that if you are ingesting Azure Security Center alerts in Azure Sentinel using the ASC connector, you will receive the warning below, which bring awareness that you may have duplication if you use this feature: 

 

Sentinel.JPG

 

Note: if you already have this integration, than the ATP for Azure Storage alerts will be already in the workspace anyway, therefore you don't need to export the alerts again.

 

Now if you want to validate, repeat the steps from my previous post to simulate the ATP for Azure Storage alert again. Once you finish, you can search for the alert in the workspace and you will see that it is there:

 

SearchforMalwareWithResult.JPG

 

 

For more information about the Continue Export feature, read this article.