Azure Sentinel - SQL Audit

Eduards 791 Reputation points
2021-01-06T07:33:33.27+00:00

Hello,

Recently i configure SQL Audit and audit server specifications to collect SQL logs and send it to Application.

Also i installed MMA agent on SQL server and configured that Event Viewer -> Application logs (MSSQLSERVER) will be delivered to Azure Sentinel.

But when i configured SQL Audit with Queue delay (43200000 miliseconds = 12 h) it's still runs audit once a 1 minute and i receive a lots of logs.. and all this logs are collected in Azure Sentinel..

Why SQL Audit Queue delay is not working properly??

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,157 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.