Nsg Log to Sentinel

Rohit 1 Reputation point
2020-07-20T07:14:04.533+00:00

Hello,

Can any one provide me the exact process/Docs/link for how to enable Azure Firewall(NSG) to Sentinel.
Or how to see the (Azure Firewall) NSG logs in Sentinel.

Thanks
Rohit

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
674 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,151 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Leon Laude 85,816 Reputation points
    2020-07-20T08:19:26.307+00:00

    Hi,

    Something here might help:

    Azure Sentinel: Collecting logs from Microsoft Services and Applications
    https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-collecting-logs-from-microsoft-services-and/ba-p/792669

    Map data types with Azure Sentinel connection options
    https://learn.microsoft.com/en-us/azure/sentinel/connect-data-sources#map-data-types-with-azure-sentinel-connection-options

    Best regards,
    Leon

    0 comments No comments

  2. Ken Golitin 21 Reputation points
    2020-07-20T08:50:42.203+00:00

    Hi,

    Enable NSG Flow logging if you want this part as well, be careful of the related storage cost
    https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics
    https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-portal

    Turn on Diagnostics logs on all NSG
    Under MONITORING, select Diagnostics logs, and then select Turn on diagnostics.
    https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log

    Collect logs for sentinel following the paragraph "How can I collect from a supported Azure source?"
    https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-collecting-logs-from-microsoft-services-and/ba-p/792669

    let me know if everything fine and mark this as answered in case it solve your issue please.
    Thank you.
    Ken

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.