[英]Azure Event Hub log sorting streaming using query
How to process Azure Log events from Event hub and filter based on criteria.如何从事件中心处理 Azure 日志事件并根据条件进行筛选。
We are trying to filter specific critical or security related Diagnostic and Activity logs before feeding into our Onprem SIEM solution.我们正在尝试在输入我们的 Onprem SIEM 解决方案之前过滤特定的关键或安全相关的诊断和活动日志。
Can someone please guide me how to filter the data from Event hub and then re-ingest into another event hub.有人可以指导我如何从事件中心过滤数据,然后重新摄取到另一个事件中心。 Whether this is possible or any other alternatives available out there.
这是否可能或任何其他可用的替代方案。
At a high level , the flow is shown below.在较高级别,流程如下所示。 Source from Diagnostic Logs (Monitor) -> Event Hub -> Filter/Query -> Event Hub enter image description here
来自诊断日志(监视器) -> 事件中心 -> 过滤器/查询 -> 事件中心在此处输入图像描述
The answer could be very bare - but in our case we are using Azure Functions to perform similar operations.答案可能非常简单 - 但在我们的例子中,我们使用 Azure Functions 来执行类似的操作。 As you know the shape of data - the function can decide if event is forwarded to other EH or it is dropped.
如您所知,数据的形状 - 该函数可以决定是将事件转发到其他 EH 还是将其丢弃。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.