Dec 27 2022 11:46 PM
Hi team ,
We are looking for solution to send logs from one sentinel workspace to another workspace which is in different subscriptions under one directory. How can we do that, I think one option will be to use event hubs but how we will do that. Also how will be the pricing for it.
Any other approaches to cater to the requirements will be helpful
Thanks
Dec 28 2022 12:06 AM
Dec 28 2022 12:39 AM
Jan 01 2023 09:45 AM - edited Jan 02 2023 01:02 AM
Hello @Prashali_Shinde,
Probably you can export data from "Log Analytics 1" into "Storage Account" under "Subscription 1" using "Logic App1" and then using "Logic App 2" pull that data from the "Storage Account" into "Log Analytics 2" in "Subscription 2". You will need to allow access from "Logic App 2" to "Storage Account" via a Private endpoint or Service endpoint.
Consider also security questions.
This can be the "Logic App1":
Azure-Sentinel/Playbooks/Move-LogAnalytics-to-Storage at master · Azure/Azure-Sentinel (github.com)
Jan 02 2023 03:05 AM
Jan 02 2023 07:10 AM