Connect Defender for Servers to Log Analytics Workspace

Richard Long 321 Reputation points
2024-06-18T21:30:59.22+00:00

We've enabled Defender for Servers and I'd like to confirm how to connect it to our Log Analytics Workspace. The Microsoft Defender XDR connector is already installed, but do we need to install the Microsoft Defender for Cloud connector for this?

The instructions in this article may be old. I don't see my workspace on the page that's referenced: https://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-enable-servers-plan#enable-the-plan-at-the-log-analytics-workspace-level

Thanks

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vlad Costa 705 Reputation points
    2024-06-18T23:39:10.0866667+00:00

    Hi @Richard Long

    The Microsoft Defender XDR connector and the Microsoft Defender for Cloud connector serve different purposes. The Defender for Cloud connector synchronizes you to the Defender for Cloud service. In contrast, the Microsoft Defender XDR connector connects you to many products in the Defender family (except Defender for Cloud).

    To connect Defender for Servers to your Log Analytics Workspace, you need to configure integration with the Log Analytics agent. Here are the steps:

    1. From the Defender for Cloud’s menu, open Environment settings.
    2. Select the relevant subscription.
    3. In the Monitoring Coverage column of the Defender plans, select Settings.
    4. From the configuration options pane, define the workspace to use.

    https://learn.microsoft.com/en-us/azure/defender-for-cloud/working-with-log-analytics-agent

    If you find this response helpful and it resolves your issue, please consider marking it as “Accepted” or giving it an upvote. This will help others in the community find the solution more easily.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Akshay-MSFT 17,486 Reputation points Microsoft Employee
    2024-06-20T13:16:12.53+00:00

    @Richard Long

    Thanks to the details shared by @Vlad Costa you need to Configure Defender for Servers features to have your data collected in LogAnalytics or Azure Monitor workspace.

    Once enabled kindly follow :https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-servers-coverage#configure-log-analytics-agent once defender for server plan 1 or 2 are enabled. Kindly refer to the snip below for reference.

    Enable workspace for defender for servers (1)

    If you don't have any further queries and the suggestion above answers your ask, please "Accept the answer", This will help us and others in the community as well.

    Thanks,

    Akshay Kaushik

    1 person found this answer helpful.
    0 comments No comments