How can I connect GNS3 network to Microsoft Sentinel?

Miloslav Šťastný 21 Reputation points
2022-05-13T18:17:26.987+00:00

Hello,
I am trying to use a GNS3 network as input data to Microsoft Sentinel. My GNS3 server with GNS3 network is running on a virtual Linux machine, so I can monitor it with Syslog connector successfully. However I am unable to detect anything from the GNS3 network. Any idead how to solve this? I would be grategul for any answer.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
6,983 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
959 questions
{count} votes

Accepted answer
  1. David Broggy 5,671 Reputation points MVP
    2022-05-26T04:32:21.01+00:00

    Hi @Miloslav Šťastný
    Microsoft Sentinel expects that any servers you want to monitor are running their monitoring agent.
    In the Azure portal, type ‘log analytics workspace’ in the top search box.
    Open the Log Analytics Workspace that is associated with your Sentinel configuration.
    Select the ‘Agents’ section and go to the Linux tab.
    You will see a curl command you can use to download and install the Azure Monitor (OMS) agent.
    Once this agent is installed you should have logs showing up in Sentinel as described in the Windows Security Events connector configuration (in the Sentinel > Connectors UI)


1 additional answer

Sort by: Most helpful
  1. Miloslav Šťastný 21 Reputation points
    2022-05-26T11:58:59.337+00:00

    Thank you for your help, I have eventually solved it.

    0 comments No comments