Can we use a single Linux/ Windows agent to collect logs from multiple log sources in Sentinel?

%3CLINGO-SUB%20id%3D%22lingo-sub-1357346%22%20slang%3D%22en-US%22%3ECan%20we%20use%20a%20single%20Linux%2F%20Windows%20agent%20to%20collect%20logs%20from%20multiple%20log%20sources%20in%20Sentinel%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1357346%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20we%20use%20a%20single%20Linux%2F%20Windows%20agent%20to%20collect%20logs%20from%20multiple%20log%20sources%20in%20Sentinel%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EMitesh%20Agrawal%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1357346%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Sentinel%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESentinel%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esyslog%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1357354%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20use%20a%20single%20Linux%2F%20Windows%20agent%20to%20collect%20logs%20from%20multiple%20log%20sources%20in%20Sentinel%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1357354%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F539205%22%20target%3D%22_blank%22%3E%40MiteshAgrawal%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20you%20can%20do%20that%20with%20Windows.%20Though%20I%20wouldn't%20be%20able%20to%20tell%20how%20to%20do%20that%20in%20Linux.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1357373%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20use%20a%20single%20Linux%2F%20Windows%20agent%20to%20collect%20logs%20from%20multiple%20log%20sources%20in%20Sentinel%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1357373%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F539205%22%20target%3D%22_blank%22%3E%40MiteshAgrawal%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20configure%20the%20MMA%20(Windows%20and%20Linux)%26nbsp%3B%20in%20the%20Log%20Analytics%20-%20Advanced%20Settings%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20add%20multiple%20sources%20to%20each%20platform.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fagent-data-sources%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fagent-data-sources%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Annotation%202020-05-04%20112847.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F188679iC41ABDACD2C81BEF%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Annotation%202020-05-04%20112847.jpg%22%20alt%3D%22Annotation%202020-05-04%20112847.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Annotation%202020-05-04%20112818.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F188678iF43503F03DC6B5F8%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Annotation%202020-05-04%20112818.jpg%22%20alt%3D%22Annotation%202020-05-04%20112818.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi Everyone,

 

Can we use a single Linux/ Windows agent to collect logs from multiple log sources in Sentinel?

 

Regards,

Mitesh Agrawal

2 Replies

@MiteshAgrawal 

Yes you can do that with Windows. Though I wouldn't be able to tell how to do that in Linux.

@MiteshAgrawal 

 

You can configure the MMA (Windows and Linux)  in the Log Analytics - Advanced Settings

 

You can add multiple sources to each platform. https://docs.microsoft.com/en-us/azure/azure-monitor/platform/agent-data-sources

 

Annotation 2020-05-04 112847.jpgAnnotation 2020-05-04 112818.jpg