How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)
Linux machines, network devices and security appliances usually send Syslog, and many security products format their Syslog messages as Common Event Format (CEF). Two connectors, Syslog via AMA and Common Event Format (CEF) via AMA, collect them with the AMA on a Linux machine.
| Syslog via AMA | CEF via AMA | |
|---|---|---|
| Message format | Plain Syslog (RFC 3164 or RFC 5424) | CEF: vendor, product, version, event class, severity and ID in a standard header, plus extensions |
| Destination table | Syslog |
CommonSecurityLog |
| DCR stream | Microsoft-Syslog |
Microsoft-CommonSecurityLog |
| Content hub solution | Syslog | Common Event Format |
rsyslog or syslog-ng. The daemon passes messages to the AMA, on TCP port 28330 for AMA 1.28.11 and later (earlier versions use a Unix domain socket), and the AMA sends them to the workspace. The forwarder can be on-premises, in Azure or in another cloud; if it isn’t an Azure VM it needs the Azure Arc Connected Machine agent.Forwarder prerequisites: a supported Linux OS, Python 2.7 or 3, and rsyslog or syslog-ng. Devices must send to the forwarder’s daemon, not their own. For a cloud forwarder, configure the daemon for TLS. For scale, a Virtual Machine Scale Set behind a round-robin load balancer is encouraged.
LOG_ERR collects LOG_ERR, LOG_CRIT, LOG_ALERT and LOG_EMERG.logger or netcat, and query the table. Logs can take up to 20 minutes to appear.The portal only lets you pick a minimum level per facility. Creating the DCR through the API is more flexible (for example, filtering specific levels), but you must install the AMA manually first and create a DCR association to the forwarder.
Using the same facility for both Syslog and CEF duplicates data across Syslog and CommonSecurityLog. Either configure sources to send CEF on facilities that the Syslog DCR doesn’t collect, or add an ingestion-time transformation to the Syslog stream that drops CEF messages:
source
| where ProcessName !contains "CEF" and SyslogMessage !contains "CEF:0"
From AMA 1.41, ProcessName might not reliably contain “CEF” for vendors that don’t follow the RFC header format, so check both fields as shown.
TimeGenerated is when the forwarder processed the message; EventTime comes from the Syslog header without a time zone and is converted using the forwarder’s offset, so the two can differ when the device is in another time zone. Extra CEF fields beyond the standard schema land in AdditionalExtensions and can add volume.
Common trap: Pointing CEF devices and Linux servers at the same forwarder facility and enabling both connectors - the same messages are ingested twice; separate facilities or filter CEF out of the Syslog stream.
This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-200 terms in the glossary · All SC-200 study notes
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.