Sysmon log collection via Azure monitor agent (AMA)

%3CLINGO-SUB%20id%3D%22lingo-sub-2634799%22%20slang%3D%22en-US%22%3ESysmon%20log%20collection%20via%20Azure%20monitor%20agent%20(AMA)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2634799%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Team%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20quick%20question%20regarding%20Azure%20monitoring%20agent.%20I%20want%20to%20capture%20Sysmon%20logs%20from%20a%20Azure%20machine%20which%20has%20AMA%20extension%20installed%20and%20data%20collection%20rule%20set%20to%20all%20events.%20I%20have%20downloaded%20Sysmon%20package%20and%20configured%20it%20on%20the%20machine%2C%20however%20is%20there%20a%20link%20to%20docs%20which%20i%20can%20follow%20to%20configure%20DCR%20(Rule)%20in%20Azure%20sentinel%20to%20allow%20Sysmon%20logs%20to%20be%20capture%20by%20AMA%20agent%3F%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20LA%20agent%20its%20quite%20simple%20to%20do%20the%20same%20as%20i%20can%20just%20go%20to%20Agent%20configurations%20and%20add%20%26gt%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3EMicrosoft-Windows-Sysmon%2FOperational%20and%20logs%20and%20its%20all%20good.%20Am%20i%20missing%20something%20%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Senior Member

Hi Team 

 

I have a quick question regarding Azure monitoring agent. I want to capture Sysmon logs from a Azure machine which has AMA extension installed and data collection rule set to all events. I have downloaded Sysmon package and configured it on the machine, however is there a link to docs which i can follow to configure DCR (Rule) in Azure sentinel to allow Sysmon logs to be capture by AMA agent? 

With LA agent its quite simple to do the same as i can just go to Agent configurations and add >  Microsoft-Windows-Sysmon/Operational and logs and its all good. Am i missing something ?

 

Thanks

 

0 Replies