Jan 05 2023 03:06 AM
Hello,
I have set up a Linux log forwarder to send syslog events from various network devices to Sentinel.
I can see these currently are sent to the CommonSecurityLog table in the Log analytics workspace.
For cost saving purposes I would like to be able to send these logs to a new table that uses the Basics Table plan.
Is that possible? It seems like it should be based on this documentation - https://learn.microsoft.com/en-us/azure/sentinel/basic-logs-use-cases
If so, is there a guide anyone can recommend on how to configure the logs to be sent to a new table that uses the Basic log storage plan.
Thanks in advance.
Jan 05 2023 08:36 AM
Jan 05 2023 03:32 PM
Jan 10 2023 05:48 AM
SolutionJan 10 2023 05:48 AM
Solution