Table in Log Analytics holding syslog messages from Linux.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500SC-200AZ-400
Each book explains Syslog in context, with comparison tables and the common traps.
Terms in this definition
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- LAMP
Short for Linux, Apache, MySQL and PHP (Perl and Python also fill the P): a widely used open-source stack for web applications whose database is frequently Azure Database for MySQL.
Related terms
- CEF
Format for text logs sent over syslog by firewalls and similar devices. A Linux log forwarder passes these messages to Microsoft Sentinel, which stores them in
CommonSecurityLog. - Guest data
Telemetry captured within a virtual machine's operating system: Windows events, Syslog, perf counters, IIS logs and text logs. Azure Monitor Agent has to be installed, with a data collection rule, before any of it is gathered.
- Linux log forwarder
Linux machine set aside to collect syslog and CEF messages from devices on port 514 using rsyslog or syslog-ng, then pass them via the Azure Monitor Agent into a Microsoft Sentinel workspace.
- Log collector
Part of Defender for Cloud Apps that you host in Docker on your own network. Your firewalls and proxies send it logs by FTP or Syslog, and it uploads them so Cloud Discovery reports stay up to date.
- Log forwarder
A Linux server set aside to collect CEF and Syslog messages from devices, by default on port 514, using rsyslog or syslog-ng, and pass them through the Azure Monitor Agent to the Microsoft Sentinel workspace.
- Microsoft Threat Intelligence Analytics
A Microsoft Sentinel rule built from a template that cannot be edited. It checks Windows DNS, CEF and Syslog data for matches with indicators from Microsoft's threat intelligence and raises high-fidelity alerts when it finds them.
- Syslog via AMA
Brings syslog from Linux machines into the Syslog table for Microsoft Sentinel, using AMA plus a DCR that chooses facilities and minimum log levels. Windows machines are out of scope.
- Windows Event Forwarding
Using subscriptions, this Windows capability sends event log entries from source machines to a collector server. CEF and syslog are not things it can receive.