Brings syslog from Linux machines into the Syslog table for Microsoft Sentinel, using AMA plus a DCR that chooses facilities and minimum log levels. Windows machines are out of scope.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Syslog via AMA in context, with comparison tables and the common traps.
Terms in this definition
- Syslog
Table in Log Analytics holding syslog messages from Linux.
- LAMP
Short for Linux, Apache, MySQL and PHP (Perl and Python also fill the P): a widely used open-source stack for web applications whose database is frequently Azure Database for MySQL.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Azure Monitor agent
Agent now used to collect logs from a machine's guest OS, driven by data collection rules; it took over from the Log Analytics agent (MMA).
- Data collection rule
Rule in Azure Monitor specifying what the Azure Monitor Agent or Logs Ingestion API gathers (XPath event filters, for example), any transformation applied, and the destination.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.