Forum Discussion

Antony Paul's avatar
Antony Paul
Copper Contributor
Jan 05, 2023

Using Basic Logs for forwarded syslog events?

Hello,

 

I have set up a Linux log forwarder to send syslog events from various network devices to Sentinel.

 

I can see these currently are sent to the CommonSecurityLog table in the Log analytics workspace.

 

For cost saving purposes I would like to be able to send these logs to a new table that uses the Basics Table plan.

 

Is that possible?  It seems like it should be based on this documentation - https://learn.microsoft.com/en-us/azure/sentinel/basic-logs-use-cases

 

If so, is there a guide anyone can recommend on how to configure the logs to be sent to a new table that uses the Basic log storage plan.

 

Thanks in advance.

 

  • -jmn-'s avatar
    -jmn-
    Jan 10, 2023
    I would recommend the AMA, the OMS becomes end-of-life on August 31st 2024.

Resources