[英]How to get Windows Security Events in Azure Log Analytics Workspace?
I have several virtual machines and virtual machine scale sets in Azure for which I want to collect Windows Security event logs.我在 Azure 中有几个虚拟机和虚拟机规模集,我想为其收集 Windows 安全事件日志。 I attempted to add these events to the Log Analytics workspace used by Sentinel through the portal.我尝试通过门户将这些事件添加到 Sentinel 使用的 Log Analytics 工作区。
This produces the following error message.这会产生以下错误消息。
'Security' event log cannot be collected by this intelligence pack because Audit Success and Audit Failure event types are not currently supported.此情报包无法收集“安全”事件日志,因为当前不支持审核成功和审核失败事件类型。
It's a hard requirement for me that Sentinel has access these Security logs. Sentinel 可以访问这些安全日志对我来说是一个硬性要求。 I've been trying to figure out what my options are, and I haven't found a good one yet.我一直在试图弄清楚我的选择是什么,但我还没有找到一个好的选择。
The prescribed approach appears to be setting up a Data Connector in Sentinel for the Security Events. 规定的方法似乎是在 Sentinel 中为安全事件设置数据连接器。 I hit a couple of interesting things attempting this.我尝试了一些有趣的事情。
Virtual machine scale sets support is limited.虚拟机规模集支持有限。 No actions are available at this moment.目前没有可用的操作。
It looks like I can't connect virtual machine scale sets, which is a big problem.看起来我无法连接虚拟机规模集,这是一个大问题。 Additionally, I can't even select the tier of the security events (see below) from this context.此外,我什至不能从这个上下文中 select 安全事件层(见下文)。
So it looks like I have to use Azure Security Center.所以看起来我必须使用 Azure 安全中心。 From within Azure Security Center the only way I can add these Security Events is to turn on Auto-Provisioning and install the Microsoft Monitoring agent (MMA) on every VM, something I don't want to do.在 Azure 安全中心内,我可以添加这些安全事件的唯一方法是打开自动配置并在每个 VM 上安装 Microsoft 监控代理 (MMA),这是我不想做的事情。 I'm also concerned about costs using ASC.我也担心使用 ASC 的成本。
Are there any other options?还有其他选择吗? Am I going about this the wrong way?我会以错误的方式解决这个问题吗?
The Security event log is automatically added behind the scenes when adding the monitoring agent on the VM.在 VM 上添加监控代理时,会在后台自动添加安全事件日志。
In regards to the VMSS, I am not sure what your options are there.关于 VMSS,我不确定您有哪些选择。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.