简体   繁体   English

如何在 Azure Log Analytics 工作区中获取 Windows 安全事件?

[英]How to get Windows Security Events in Azure Log Analytics Workspace?

I have several virtual machines and virtual machine scale sets in Azure for which I want to collect Windows Security event logs.我在 Azure 中有几个虚拟机和虚拟机规模集,我想为其收集 Windows 安全事件日志。 I attempted to add these events to the Log Analytics workspace used by Sentinel through the portal.我尝试通过门户将这些事件添加到 Sentinel 使用的 Log Analytics 工作区。

在此处输入图像描述

This produces the following error message.这会产生以下错误消息。

'Security' event log cannot be collected by this intelligence pack because Audit Success and Audit Failure event types are not currently supported.此情报包无法收集“安全”事件日志,因为当前不支持审核成功和审核失败事件类型。

It's a hard requirement for me that Sentinel has access these Security logs. Sentinel 可以访问这些安全日志对我来说是一个硬性要求。 I've been trying to figure out what my options are, and I haven't found a good one yet.我一直在试图弄清楚我的选择是什么,但我还没有找到一个好的选择。

The prescribed approach appears to be setting up a Data Connector in Sentinel for the Security Events. 规定的方法似乎是在 Sentinel 中为安全事件设置数据连接器。 I hit a couple of interesting things attempting this.我尝试了一些有趣的事情。

在此处输入图像描述

Virtual machine scale sets support is limited.虚拟机规模集支持有限。 No actions are available at this moment.目前没有可用的操作。

It looks like I can't connect virtual machine scale sets, which is a big problem.看起来我无法连接虚拟机规模集,这是一个大问题。 Additionally, I can't even select the tier of the security events (see below) from this context.此外,我什至不能从这个上下文中 select 安全事件层(见下文)。

在此处输入图像描述

So it looks like I have to use Azure Security Center.所以看起来我必须使用 Azure 安全中心。 From within Azure Security Center the only way I can add these Security Events is to turn on Auto-Provisioning and install the Microsoft Monitoring agent (MMA) on every VM, something I don't want to do.在 Azure 安全中心内,我可以添加这些安全事件的唯一方法是打开自动配置并在每个 VM 上安装 Microsoft 监控代理 (MMA),这是我不想做的事情。 I'm also concerned about costs using ASC.我也担心使用 ASC 的成本。

Are there any other options?还有其他选择吗? Am I going about this the wrong way?我会以错误的方式解决这个问题吗?

The Security event log is automatically added behind the scenes when adding the monitoring agent on the VM.在 VM 上添加监控代理时,会在后台自动添加安全事件日志。

In regards to the VMSS, I am not sure what your options are there.关于 VMSS,我不确定您有哪些选择。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

相关问题 如何使用 az CLI 获取 Azure Log Analytics 的工作区 ID? - How to get workspace ID of Azure Log Analytics using az CLI? 如何轮换 Azure 日志分析工作区的密钥 - How to rotate keys for azure log analytics workspace 如何通过C#获取Azure Log Analytics工作区的工作区ID - How to get the Workspace ID of an Azure Log Analytics workspace via C# 如何通过 PowerShell 脚本从 Azure Log Analytics 工作区获取自定义日志表? - How to get Custom Log tables from Azure Log Analytics Workspace through PowerShell script? Azure Log Analytics 工作区和 GDPR - Azure Log Analytics Workspace and GDPR 如何通过 powershell 将 PostgreSQL 数据库连接到 azure 中的日志分析工作区? - How to connect PostgreSQL database to log analytics workspace in azure via powershell? 如何连接 Azure 中现有的自动化帐户和 Log Analytics 工作区? - How to connect existing Automation Account and Log Analytics workspace in Azure? 如何在 azure 门户中永久删除旧的 Log-analytics-workspace? - How to delete old Log-analytics-workspace permanently in azure portal? 如何在 Azure Log Analytics 工作区中启用 Client_IP - How to enable Client_IP in Azure Log Analytics Workspace 获取 Azure 中连接到不同订阅中的工作区的虚拟机的 Log Analytics 工作区 ID - Get Log analytics workspace ID of a virtual machine in Azure connected to a workspace in a different subscription
 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM