A Linux server set aside to collect CEF and Syslog messages from devices, by default on port 514, using rsyslog or syslog-ng, and pass them through the Azure Monitor Agent to the Microsoft Sentinel workspace.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Log forwarder in context, with comparison tables and the common traps.
Terms in this definition
- LAMP
Short for Linux, Apache, MySQL and PHP (Perl and Python also fill the P): a widely used open-source stack for web applications whose database is frequently Azure Database for MySQL.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- CEF
Format for text logs sent over syslog by firewalls and similar devices. A Linux log forwarder passes these messages to Microsoft Sentinel, which stores them in
CommonSecurityLog. - Syslog
Table in Log Analytics holding syslog messages from Linux.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- Azure Monitor agent
Agent now used to collect logs from a machine's guest OS, driven by data collection rules; it took over from the Log Analytics agent (MMA).
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
Related terms
- CommonSecurityLog
Destination table in Log Analytics for CEF-formatted messages that a Microsoft Sentinel log forwarder passes on.
- Custom Logs via AMA
Collects text-file logs into a _CL table, using the Azure Monitor Agent plus a data collection rule, from Windows or Linux machines or a log forwarder. It is a Microsoft Sentinel data connector still in preview.