SOLVED

Server core event logs

%3CLINGO-SUB%20id%3D%22lingo-sub-2274831%22%20slang%3D%22en-US%22%3EServer%20core%20event%20logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2274831%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20been%20using%20the%20Log%20Analytics%20agent%20to%20get%20on-premise%20server%20event%20logs%20into%20Sentinel%20and%20all%20has%20gone%20well%20with%20the%20exception%20for%20Server%20core%20boxes.%20Server%20Core%20isn't%20listed%20as%20supported%20(%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fagents%2Fagents-overview%23log-analytics-agent%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fagents%2Fagents-overview%23log-analytics-agent%3C%2FA%3E)%20so%20was%20wondering%20what%20is%20the%20best%20way%20to%20get%20server%20core%20logs%20over%20into%20Sentinel.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I have been using the Log Analytics agent to get on-premise server event logs into Sentinel and all has gone well with the exception for Server core boxes. Server Core isn't listed as supported (

https://docs.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview#log-analytics-agent) so was wondering what is the best way to get server core logs over into Sentinel.

3 Replies
best response confirmed by fishermc (Occasional Contributor)
Solution
You will need WEF/WEC but support for that will be added in a future release of the Azure Monitor Agent.
Just curious if happen to know when that future release might be? Something like or 1 or 2 months or as long as a year?

Thanks for the response to the initial question.
Sorry its an NDA item, are you a member of the Private Preview (if your company has an NDA with Microsoft, you can signup in the Azure Sentinel Portal - News & Guides - What's New - Private Preview link: https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR-kibZAPJAVBiU46J6wWF_5URDFS...)