SOLVED

Setting the security event option - 'Common' events

%3CLINGO-SUB%20id%3D%22lingo-sub-2132266%22%20slang%3D%22en-US%22%3ESetting%20the%20security%20event%20option%20-%20'Common'%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2132266%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20community%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20wonder%20if%20you%20can%20help%20me%20out%3F%20I%20am%20trying%20to%20find%20where%20to%20set%20the%20security%20event%20option%20for%20%3CSTRONG%3EWindows%20events%20(All%2C%20Common%2C%20Minimal%2C%20None).%3C%2FSTRONG%3E%20The%20documentation%20states%3A%20Go%20to%3CSPAN%3E%26nbsp%3BSecurity%20Center's%20menu%20in%20the%20Azure%20portal%2C%20select%26nbsp%3B%3C%2FSPAN%3EPricing%20%26amp%3B%20settings%2C%20on%20Data%20Collection%20set%20the%20event%20level%20you%20need.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20when%20I%20do%20that%20all%20my%20options%20are%20greyed%20out.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20a%20message%20that%20reads%20%3CEM%3E%22Security%20Events%20tier%20configuration%20is%20shared%20with%20Azure%20Sentinel%20and%20was%20already%20configured%20there%20to%20'Common'%20for%20the%20selected%20workspace.%20Please%20change%20the%20tier%20in%20Azure%20Sentinel%20and%20it%20will%20apply%20for%20Azure%20Security%20Center%20as%20well.%20Please%20note%20that%20Security%20events%20will%20be%20collected%20once%20and%20used%20in%20both%20solutions.%22%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWhen%20I%20go%20to%20my%20Azure%20Sentinel%20workspace%20I%20cannot%20find%20where%20these%20settings%20are%20located.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%20in%20advance.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2132304%22%20slang%3D%22en-US%22%3ERe%3A%20Setting%20the%20security%20event%20option%20-%20'Common'%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2132304%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F964989%22%20target%3D%22_blank%22%3E%40challengelogic%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20the%20options%20are%20greyed%20out%20because%20of%20this%20%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EUsers%20of%20Azure%20Sentinel%3A%20note%20that%20security%20events%20collection%20within%20the%20context%20of%20a%20single%20workspace%20can%20be%20configured%20from%20either%20Azure%20Security%20Center%20or%20Azure%20Sentinel%2C%20but%20not%20both.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EIf%20you%20want%20to%20stick%20to%20Azure%20Security%20Center%20you%20have%20to%20do%20the%20following%20%3A%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDisable%20Security%20Events%20collection%20in%20Azure%20Security%20Center%20(by%20setting%26nbsp%3B%3CSTRONG%3EWindows%20security%20events%3C%2FSTRONG%3E%26nbsp%3Bto%26nbsp%3B%3CSTRONG%3ENone%3C%2FSTRONG%3E%26nbsp%3Bin%20the%20configuration%20of%20your%20Log%20Analytics%20agent).%20Then%20add%20the%20Security%20Events%20connector%20in%20Azure%20Sentinel.%20As%20with%20the%20first%20option%2C%20you%20will%20be%20able%20to%20query%20and%20analyze%20events%20in%20both%20Azure%20Sentinel%20and%20Azure%20Defender%2FASC%2C%20but%20you%20will%20now%20be%20able%20to%20monitor%20the%20connector's%20connectivity%20status%20or%20change%20its%20configuration%20in%20-%20and%20only%20in%20-%20Azure%20Sentinel%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDoc%20Ref%20%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-enable-data-collection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-enable-data-collection%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2133237%22%20slang%3D%22en-US%22%3ERe%3A%20Setting%20the%20security%20event%20option%20-%20'Common'%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2133237%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F540591%22%20target%3D%22_blank%22%3E%40ibrahimambodji%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20taking%20the%20time%20to%20reply%20to%20my%20question%2C%20appreciated!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20understand%20that%20those%20security%20event%20settings%20need%20to%20be%20either%20ASC%20or%20Sentinel%20and%20not%20both.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20do%20we%20instruct%20the%20client%20agents%20to%20use%20Common%20or%20All%20events%3F%20This%20is%20the%20part%20I'm%20not%20understanding%20as%20I%20cannot%20find%20where%20we%20make%20that%20'choice'%20from%20the%20Sentinel%20blade%20%2F%20config%20pages.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20want%20my%20client%20Agents%20to%20use%20'common'%20(over%20all%2C%20minimal%20or%20none)%20-%20where%20is%20this%20defined%3F%20And%20how%20do%20I%20determine%20what%20the%20configuration%20is%20set%20to%20(for%20example%2C%20where%20I%20inherit%20an%20existing%20Sentinel%20deployment%20etc)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2133305%22%20slang%3D%22en-US%22%3ERe%3A%20Setting%20the%20security%20event%20option%20-%20'Common'%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2133305%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F964989%22%20target%3D%22_blank%22%3E%40challengelogic%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20it%20is%20defined%20in%20Security%20Center%26nbsp%3B%20so%20you%20need%20to%26nbsp%3B%20disable%20it%20from%20security%20center%20to%20be%20able%20to%20use%20it%20in%20Sentinel%26nbsp%3B%20.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E%26nbsp%3BDisable%26nbsp%3B%20Security%20event%20collecton%26nbsp%3B%20in%20Azure%20Security%20Cen%3C%2FSTRONG%3Eter%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EFrom%20Security%20Center's%20menu%2C%20select%26nbsp%3BPricing%20%26amp%3B%20settings.%3C%2FLI%3E%3CLI%3ESelect%20the%20relevant%20subscription.%3C%2FLI%3E%3CLI%3EIn%20the%26nbsp%3BAuto%20provisioning%26nbsp%3Bpage%2C%20set%20the%20agent's%20status%20to%26nbsp%3BOn.%3C%2FLI%3E%3CLI%3EFrom%20the%20configuration%20options%20pane%2C%20define%20the%20workspace%20to%20use.%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-enable-data-collection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ERef%20%3A%26nbsp%3B%20Auto-deploy%20agents%20for%20Azure%20Security%20Center%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2133331%22%20slang%3D%22en-US%22%3ERe%3A%20Setting%20the%20security%20event%20option%20-%20'Common'%20events%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2133331%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F964989%22%20target%3D%22_blank%22%3E%40challengelogic%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ESet%20up%20the%20Windows%20Security%20Events%20connector%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3ETo%20collect%20your%20Windows%20security%20events%20in%20Azure%20Sentinel%3A%3C%2FP%3E%3COL%3E%3CLI%3EFrom%20the%20Azure%20Sentinel%20navigation%20menu%2C%20select%26nbsp%3BData%20connectors.%20From%20the%20list%20of%20connectors%2C%20click%20on%26nbsp%3BSecurity%20Events%2C%20and%20then%20on%20the%26nbsp%3BOpen%20connector%20page%26nbsp%3Bbutton%20on%20the%20lower%20right.%20Then%20follow%20the%20on-screen%20instructions%20under%20the%26nbsp%3BInstructions%26nbsp%3Btab%2C%20as%20described%20through%20the%20rest%20of%20this%20section.%3C%2FLI%3E%3CLI%3EVerify%20that%20you%20have%20the%20appropriate%20permissions%20as%20described%20under%20the%26nbsp%3BPrerequisites%26nbsp%3Bsection%20on%20the%20connector%20page.%3C%2FLI%3E%3CLI%3EDownload%20and%20install%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Flog-analytics-agent%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ELog%20Analytics%20agent%3C%2FA%3E%26nbsp%3B(also%20known%20as%20the%20Microsoft%20Monitoring%20Agent%20or%20MMA)%20on%20the%20machines%20for%20which%20you%20want%20to%20stream%20security%20events%20into%20Azure%20Sentinel.For%20Azure%20Virtual%20Machines%3A%3COL%3E%3CLI%3EClick%20on%26nbsp%3BInstall%20agent%20on%20Azure%20Windows%20Virtual%20Machine%2C%20and%20then%20on%20the%20link%20that%20appears%20below.%3C%2FLI%3E%3CLI%3EFor%20each%20virtual%20machine%20that%20you%20want%20to%20connect%2C%20click%20on%20its%20name%20in%20the%20list%20that%20appears%20on%20the%20right%2C%20and%20then%20click%26nbsp%3BConnect.%3C%2FLI%3E%3C%2FOL%3EFor%20non-Azure%20Windows%20machines%20(physical%2C%20virtual%20on-prem%2C%20or%20virtual%20in%20another%20cloud)%3A%3COL%3E%3CLI%3EClick%20on%26nbsp%3BInstall%20agent%20on%20non-Azure%20Windows%20Machine%2C%20and%20then%20on%20the%20link%20that%20appears%20below.%3C%2FLI%3E%3CLI%3EClick%20on%20the%20appropriate%20download%20links%20that%20appear%20on%20the%20right%2C%20under%26nbsp%3BWindows%20Computers.%3C%2FLI%3E%3CLI%3EUsing%20the%20downloaded%20executable%20file%2C%20install%20the%20agent%20on%20the%20Windows%20systems%20of%20your%20choice%2C%20and%20configure%20it%20using%20the%26nbsp%3BWorkspace%20ID%20and%20Keys%26nbsp%3Bthat%20appear%20below%20the%20download%20links%20mentioned%20above.%3C%2FLI%3E%3CLI%3E%3CP%3EFor%20additional%20installation%20options%20and%20further%20details%2C%20see%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fagent-windows%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3ELog%20Analytics%20agent%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Edocumentation%3C%2FA%3E.%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3ESelect%20which%20event%20set%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-windows-security-events%23event-sets%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAll%2C%20Common%2C%20or%20Minimal%3C%2FA%3E)%20you%20want%20to%20stream.%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3EClick%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EUpdate%3C%2FSTRONG%3E.%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3ETo%20use%20the%20relevant%20schema%20in%20Log%20Analytics%20for%20Windows%20security%20events%2C%20type%20SecurityEvent%20in%20the%20query%20window.%3C%2FP%3EValidate%20Connectivity%3CP%3EIt%20may%20take%20around%2020%20minutes%20until%20your%20logs%20start%20to%20appear%20in%20Log%20Analytics.%3C%2FP%3E%3C%2FLI%3E%3C%2FOL%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3EFull%20documentation%20%3A%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-windows-security-events%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EConnect%20Windows%20security%20event%20data%20to%20Azure%20Sentinel%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello community

 

I wonder if you can help me out? I am trying to find where to set the security event option for Windows events (All, Common, Minimal, None). The documentation states: Go to Security Center's menu in the Azure portal, select Pricing & settings, on Data Collection set the event level you need.

 

However when I do that all my options are greyed out.

 

There is a message that reads "Security Events tier configuration is shared with Azure Sentinel and was already configured there to 'Common' for the selected workspace. Please change the tier in Azure Sentinel and it will apply for Azure Security Center as well. Please note that Security events will be collected once and used in both solutions."

 

When I go to my Azure Sentinel workspace I cannot find where these settings are located.

 

Thanks in advance.

 

6 Replies

@challengelogic 

 

Hi the options are greyed out because of this : 

Users of Azure Sentinel: note that security events collection within the context of a single workspace can be configured from either Azure Security Center or Azure Sentinel, but not both.

 

If you want to stick to Azure Security Center you have to do the following :

 

Disable Security Events collection in Azure Security Center (by setting Windows security events to None in the configuration of your Log Analytics agent). Then add the Security Events connector in Azure Sentinel. As with the first option, you will be able to query and analyze events in both Azure Sentinel and Azure Defender/ASC, but you will now be able to monitor the connector's connectivity status or change its configuration in - and only in - Azure Sentinel

 

Doc Ref : https://docs.microsoft.com/en-us/azure/security-center/security-center-enable-data-collection

@ibrahimambodji 

 

Thank you for taking the time to reply to my question, appreciated!

 

I understand that those security event settings need to be either ASC or Sentinel and not both. 

 

How do we instruct the client agents to use Common or All events? This is the part I'm not understanding as I cannot find where we make that 'choice' from the Sentinel blade / config pages.

 

If I want my client Agents to use 'common' (over all, minimal or none) - where is this defined? And how do I determine what the configuration is set to (for example, where I inherit an existing Sentinel deployment etc)

 

thank you.

@challengelogic 

Hi it is defined in Security Center  so you need to  disable it from security center to be able to use it in Sentinel  . 

 Disable  Security event collecton  in Azure Security Center

 

  1. From Security Center's menu, select Pricing & settings.
  2. Select the relevant subscription.
  3. In the Auto provisioning page, set the agent's status to On.
  4. From the configuration options pane, define the workspace to use.

Ref :  Auto-deploy agents for Azure Security Center | Microsoft Docs

 

 

Best Response confirmed by challengelogic (Occasional Contributor)
Solution

@challengelogic 

Set up the Windows Security Events connector

To collect your Windows security events in Azure Sentinel:

  1. From the Azure Sentinel navigation menu, select Data connectors. From the list of connectors, click on Security Events, and then on the Open connector page button on the lower right. Then follow the on-screen instructions under the Instructions tab, as described through the rest of this section.
  2. Verify that you have the appropriate permissions as described under the Prerequisites section on the connector page.
  3. Download and install the Log Analytics agent (also known as the Microsoft Monitoring Agent or MMA) on the machines for which you want to stream security events into Azure Sentinel.For Azure Virtual Machines:
    1. Click on Install agent on Azure Windows Virtual Machine, and then on the link that appears below.
    2. For each virtual machine that you want to connect, click on its name in the list that appears on the right, and then click Connect.
    For non-Azure Windows machines (physical, virtual on-prem, or virtual in another cloud):
    1. Click on Install agent on non-Azure Windows Machine, and then on the link that appears below.
    2. Click on the appropriate download links that appear on the right, under Windows Computers.
    3. Using the downloaded executable file, install the agent on the Windows systems of your choice, and configure it using the Workspace ID and Keys that appear below the download links mentioned above.
    4. For additional installation options and further details, see the Log Analytics agent documentation.

    5. Select which event set (All, Common, or Minimal) you want to stream.

    6. Click Update.

    7. To use the relevant schema in Log Analytics for Windows security events, type SecurityEvent in the query window.

      Validate Connectivity

      It may take around 20 minutes until your logs start to appear in Log Analytics.

Full documentation :  Connect Windows security event data to Azure Sentinel | Microsoft Docs

@ibrahimambodji - Again, thank you for the clarification around this. Many thanks!

@challengelogic 

 

You're welcome .Happy to see that it's helpful