Can we use a single Linux/ Windows agent to collect logs from multiple log sources in Sentinel?

Brass Contributor

Hi Everyone,

 

Can we use a single Linux/ Windows agent to collect logs from multiple log sources in Sentinel?

 

Regards,

Mitesh Agrawal

2 Replies

@MiteshAgrawal 

Yes you can do that with Windows. Though I wouldn't be able to tell how to do that in Linux.

@MiteshAgrawal 

 

You can configure the MMA (Windows and Linux)  in the Log Analytics - Advanced Settings

 

You can add multiple sources to each platform. https://docs.microsoft.com/en-us/azure/azure-monitor/platform/agent-data-sources

 

Annotation 2020-05-04 112847.jpgAnnotation 2020-05-04 112818.jpg