FREE STUDY NOTES · SC-200

Syslog via AMA vs CEF via AMA: tables, forwarders and duplicates

How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.

From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)

Linux machines, network devices and security appliances usually send Syslog, and many security products format their Syslog messages as Common Event Format (CEF). Two connectors, Syslog via AMA and Common Event Format (CEF) via AMA, collect them with the AMA on a Linux machine.

Syslog via AMA CEF via AMA
Message format Plain Syslog (RFC 3164 or RFC 5424) CEF: vendor, product, version, event class, severity and ID in a standard header, plus extensions
Destination table Syslog CommonSecurityLog
DCR stream Microsoft-Syslog Microsoft-CommonSecurityLog
Content hub solution Syslog Common Event Format

Architecture

Forwarder prerequisites: a supported Linux OS, Python 2.7 or 3, and rsyslog or syslog-ng. Devices must send to the forwarder’s daemon, not their own. For a cloud forwarder, configure the daemon for TLS. For scale, a Virtual Machine Scale Set behind a round-robin load balancer is encouraged.

Setting it up

  1. Install the Syslog or Common Event Format solution from the content hub.
  2. On the connector page, select +Create data collection rule: name and resource group, select the forwarder on Resources (the AMA is installed automatically), then on Collect choose the minimum log level per facility. Selecting LOG_ERR collects LOG_ERR, LOG_CRIT, LOG_ALERT and LOG_EMERG.
  3. On the forwarder, run the installation script from the connector page. It configures the daemon, opens port 514 for UDP and TCP and restarts it.
  4. Configure the devices to send to the forwarder, then test, for example with logger or netcat, and query the table. Logs can take up to 20 minutes to appear.

The portal only lets you pick a minimum level per facility. Creating the DCR through the API is more flexible (for example, filtering specific levels), but you must install the AMA manually first and create a DCR association to the forwarder.

Avoiding duplicates

Using the same facility for both Syslog and CEF duplicates data across Syslog and CommonSecurityLog. Either configure sources to send CEF on facilities that the Syslog DCR doesn’t collect, or add an ingestion-time transformation to the Syslog stream that drops CEF messages:

source
| where ProcessName !contains "CEF" and SyslogMessage !contains "CEF:0"

From AMA 1.41, ProcessName might not reliably contain “CEF” for vendors that don’t follow the RFC header format, so check both fields as shown.

TimeGenerated is when the forwarder processed the message; EventTime comes from the Syslog header without a time zone and is converted using the forwarder’s offset, so the two can differ when the device is in another time zone. Extra CEF fields beyond the standard schema land in AdditionalExtensions and can add volume.

Common trap: Pointing CEF devices and Linux servers at the same forwarder facility and enabling both connectors - the same messages are ingested twice; separate facilities or filter CEF out of the Syslog stream.

Get the whole book

This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-200 terms in the glossary · All SC-200 study notes

More SC-200 study notes