different ways to collect Security Events using Log Analytics agent ?

AdamBudzinskiAZA-0329 96 Reputation points
2022-09-08T14:35:34.69+00:00

Hi,

Anyone can please tell me what’s the difference between enabling Security Event collection with Log Analytics agent using this:
a) Defender for Cloud > Environment Settings > Subscription > Auto provisioning

frist

versus

b) Defender for Cloud > Environment Settings > Subscription > Log Analytics workspace

second

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

Accepted answer
  1. Andrew Blumhardt 10,051 Reputation points Microsoft Employee
    2022-09-09T12:34:45.273+00:00

    I see. The first under auto provisioning applies to all workspaces in the subscription that have been activated for MDFC (they have the provider installed). It is possible to have MDFC on more than one workspace. The second option is for setting this at the workspace level. These settings may change soon as MDFC increase support for the new AMA agent\DCR rules. Most only configure this on the Sentinel side or not at all.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,051 Reputation points Microsoft Employee
    2022-09-08T15:21:14.247+00:00

    MDFC has the option to gather security events for hunting. MDFC does not use this data specifically, it is a collection only option. Sentinel also collects Windows Security events and relies on those events heavily for detection. The portal will prevent collecting from both simultaneously. Sentinel is preferred as the collection method if you use both. If you do not have Sentinel, then consider this optional for MDFC. Also, the 500MB per day allotment for data collection should cover the Security alert data but high-volume systems like a busy DC can run over 500MB and incur an additional log ingestion cost.

    2 people found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.