Unable to integrate suse linux (azure VM) on azure sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-1080859%22%20slang%3D%22en-US%22%3EUnable%20to%20integrate%20suse%20linux%20(azure%20VM)%20on%20azure%20sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1080859%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20experts%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20facing%20a%20challenge%20while%20integrating%20Azure%20VM%20suse%20linux%20using%20syslog%20dataconnector.%20I%20have%20configured%20levels%20and%20connected%20to%20the%20VM%20to%20the%20workspace.%20But%20still%20it%20is%20not%20showing%20as%20connected%20in%20data%20connectors%20page.%20Please%20suggest%20what%20could%20be%20the%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewhat%20is%20the%20agent%20used%20to%20collect%20it%3F%20is%20is%20same%20to%20that%20of%20Azure%20Monitor.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1080886%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20integrate%20suse%20linux%20(azure%20VM)%20on%20azure%20sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1080886%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F493793%22%20target%3D%22_blank%22%3E%40Jayesh_D123%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20servers%20are%20in%20a%20protected%20region%20with%20no%20internet%20access.%20So%20what%20needs%20to%20be%20enabled%20between%20VM%20and%20workspace.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1081032%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20integrate%20suse%20linux%20(azure%20VM)%20on%20azure%20sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1081032%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F493793%22%20target%3D%22_blank%22%3E%40Jayesh_D123%3C%2FA%3E%26nbsp%3Byes%20this%20is%20the%20same%20agent%20(%20MMA%5CAzure%20monitor)%3C%2FP%3E%0A%3CP%3EYou%20can%20see%20here%20the%20SUSE%20linux%20is%20supported%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fmicrosoft%2FOMS-Agent-for-Linux%23supported-linux-operating-systems%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2Fmicrosoft%2FOMS-Agent-for-Linux%23supported-linux-operating-systems%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ethis%20is%20the%20urls%20that%20you%20need%20to%20enable%20in%20the%20FW%5Cproxy%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Flog-analytics-agent%23network-firewall-requirements%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Flog-analytics-agent%23network-firewall-requirements%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084151%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20integrate%20suse%20linux%20(azure%20VM)%20on%20azure%20sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084151%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F493793%22%20target%3D%22_blank%22%3E%40Jayesh_D123%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20is%20a%20write-up%20on%20how%20to%20configure%20it%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-syslog%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fdata-sources-syslog%3C%2FA%3E%3CBR%20%2F%3ESyslog%20settings%20in%20%22Advanced%20Settings%22%20are%20pushed%20towards%20the%20OMS%20Agent%20within%2010%2F15%20minutes.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20suggest%20to%20try%20to%20get%20already%20the%20logs%20from%20your%20Linux%20O.S.%20going%20to%20Azure%20Sentinel%20by%20enabling%20Syslog%20Facility%20such%20as%20%22auth%22%2C%20%22deamon%22%20and%20then%20have%20a%20look%20inside%20Azure%20Sentinel%20if%20there%20is%20data%20going%20the%20connector%20in%20the%20Data%20Connector%20blade.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20may%20need%20also%20to%20verify%20that%20there%20is%20no%20network%20filtering%20in%20place%20somewhere%20(Host-level%20firewall%2C%20...)%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EKind%20Regards%2C%3C%2FP%3E%3CP%3EThomas%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello experts,

 

I am facing a challenge while integrating Azure VM suse linux using syslog dataconnector. I have configured levels and connected to the VM to the workspace. But still it is not showing as connected in data connectors page. Please suggest what could be the issue.

 

what is the agent used to collect it? is is same to that of Azure Monitor.

3 Replies

@Jayesh_D123 

 

The servers are in a protected region with no internet access. So what needs to be enabled between VM and workspace.

@Jayesh_D123 yes this is the same agent ( MMA\Azure monitor)

You can see here the SUSE linux is supported https://github.com/microsoft/OMS-Agent-for-Linux#supported-linux-operating-systems

 

this is the urls that you need to enable in the FW\proxy https://docs.microsoft.com/en-us/azure/azure-monitor/platform/log-analytics-agent#network-firewall-r...

Hello @Jayesh_D123,

 

Here is a write-up on how to configure it: 

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-syslog
Syslog settings in "Advanced Settings" are pushed towards the OMS Agent within 10/15 minutes.

 

I would suggest to try to get already the logs from your Linux O.S. going to Azure Sentinel by enabling Syslog Facility such as "auth", "deamon" and then have a look inside Azure Sentinel if there is data going the connector in the Data Connector blade.

 

You may need also to verify that there is no network filtering in place somewhere (Host-level firewall, ...)


Kind Regards,

Thomas