SOLVED

Sentinel across multi-region/workspaces

%3CLINGO-SUB%20id%3D%22lingo-sub-1205295%22%20slang%3D%22en-US%22%3ESentinel%20across%20multi-region%2Fworkspaces%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1205295%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20resource%20deployed%20in%20two%20regions%2C%20East%20US%20and%20Central%20US.%20We%20are%20using%20Central%20US%20as%26nbsp%3Bas%20zone%20pair%20to%20East%20US%20and%20with%20that%20was%20wondering%20if%20I%20need%20to%20create%20a%20log%20analytics%20workspace%20for%20the%20resources%20in%20Central%20US%2C%20and%20if%20so%2C%20how%20do%20I%20configure%2Fassociate%20Sentinel%20to%20both%20workspaces%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThx%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1205373%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20across%20multi-region%2Fworkspaces%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1205373%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F173036%22%20target%3D%22_blank%22%3E%40Jeff%20Walzer%3C%2FA%3E%26nbsp%3BNo%20need%20to%20pair%20them.%20You%20can%20have%20multiple%20workspaces%20and%20query%20across%20them%20using%20a%20single%20Azure%20Sentinel%20console.%20Here's%20an%20example...%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eunion%20Update%2C%20workspace(%22otherworkspacename%22).Update%2C%20workspace(%22otherworkspaceID%22).Update%3CBR%20%2F%3E%7C%20where%20TimeGenerated%20%26gt%3B%3D%20ago(1h)%3CBR%20%2F%3E%7C%20where%20UpdateState%20%3D%3D%20%22Needed%22%3CBR%20%2F%3E%7C%20summarize%20dcount(Computer)%20by%20Classification%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20even%20save%20a%20query%20like%20this%20as%20a%20Function%20so%20you%20can%20just%20use%20the%20Function%20alias%20to%20use%20it.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EQuestion%20is...why%20do%20you%20think%20you%20might%20need%20multiple%20Sentinel%20workspaces%3F%20Best%20practice%20is%20to%20use%20a%20single%20workspace%20if%20possible.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EReasons%20why%20you%20might%20want%20to%20use%20multiple%20workspaces%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EUse%20of%20multiple%20Azure%20tenants%3C%2FLI%3E%0A%3CLI%3EFor%20compliance%20and%20sovereignty%20reasons%3C%2FLI%3E%0A%3CLI%3ETo%20reduce%20networking%20costs%20across%20regions%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EReasons%20to%20avoid%20multiple%20workspaces%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ESeparate%20billing%3C%2FLI%3E%0A%3CLI%3EFine%20grained%20retention%20settings%3C%2FLI%3E%0A%3CLI%3EFine%20grained%20access%20control%3C%2FLI%3E%0A%3CLI%3ELegacy%20architecture%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1206314%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20across%20multi-region%2Fworkspaces%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1206314%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F324945%22%20target%3D%22_blank%22%3E%40rodtrent%3C%2FA%3E-%20thx%20for%20the%20reply%20and%20information.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20reason%20I%20thought%20I%20would%20need%20multiple%20workspaces%20is%20because%20we%20have%20resources%20in%20different%20regions.%20Is%20it%20possible%20to%20have%20resources%20is%20one%20region%20forward%20metrics%2Fevents%20via%20the%20diagnostic%20and%20log%20analytics%20agent%20to%20another%20region%20(in%20my%20case%20resources%20in%20the%20Central%20region%20forwarding%20metrics%2Fevents%20to%20the%20East%20region)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThx%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1206464%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20across%20multi-region%2Fworkspaces%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1206464%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F173036%22%20target%3D%22_blank%22%3E%40Jeff%20Walzer%3C%2FA%3E%26nbsp%3BYes%2C%20absolutely.%20Azure%20Sentinel%20becomes%20the%20single%20pane%20of%20glass%20for%20your%20entire%20infrastructure.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207269%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20across%20multi-region%2Fworkspaces%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207269%22%20slang%3D%22en-US%22%3EThis%20webinar%20might%20interest%20you%20also%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F_mm3GNwPBHU%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fyoutu.be%2F_mm3GNwPBHU%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EAround%2058m%20they%20talk%20about%20multiple%20workspaces%20and%20your%20use%20case%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207286%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20across%20multi-region%2Fworkspaces%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207286%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E-%20TYVM%20for%20the%20link%20-%20greatly%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

We have resource deployed in two regions, East US and Central US. We are using Central US as as zone pair to East US and with that was wondering if I need to create a log analytics workspace for the resources in Central US, and if so, how do I configure/associate Sentinel to both workspaces?

 

Thx  

5 Replies
Highlighted
Best Response confirmed by Jeff Walzer (Contributor)
Solution

@Jeff Walzer No need to pair them. You can have multiple workspaces and query across them using a single Azure Sentinel console. Here's an example...

 

union Update, workspace("otherworkspacename").Update, workspace("otherworkspaceID").Update
| where TimeGenerated >= ago(1h)
| where UpdateState == "Needed"
| summarize dcount(Computer) by Classification

 

You can even save a query like this as a Function so you can just use the Function alias to use it.

 

Question is...why do you think you might need multiple Sentinel workspaces? Best practice is to use a single workspace if possible.

 

Reasons why you might want to use multiple workspaces:

  • Use of multiple Azure tenants
  • For compliance and sovereignty reasons
  • To reduce networking costs across regions

 

Reasons to avoid multiple workspaces:

  • Separate billing
  • Fine grained retention settings
  • Fine grained access control
  • Legacy architecture

 

Highlighted

@rodtrent- thx for the reply and information.

 

The reason I thought I would need multiple workspaces is because we have resources in different regions. Is it possible to have resources is one region forward metrics/events via the diagnostic and log analytics agent to another region (in my case resources in the Central region forwarding metrics/events to the East region)?

 

Thx

Highlighted

@Jeff Walzer Yes, absolutely. Azure Sentinel becomes the single pane of glass for your entire infrastructure.

Highlighted
This webinar might interest you also: https://youtu.be/_mm3GNwPBHU

Around 58m they talk about multiple workspaces and your use case
Highlighted

@Thijs Lecomte- TYVM for the link - greatly appreciated