Buffer en Azure Monitor Agent

Abel Cajaraville Capote 1 Reputation point
2023-01-02T14:35:44.433+00:00

We are migrating our onpremise SIEM to Azure Sentinel.
We have 3 forwarding servers with the AMA agent (2 syslog/CEF and 1 Wec).
We want that when a VPN tunnel goes down the agent buffer is able to store at least 10 GB.
Is this possible?
If not, what is the limit and where can we configure them for Linux and Windows agents?

Thank you very much

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Alexandros Rapsomanikis 10 Reputation points
    2025-02-12T15:32:54.39+00:00

    Hi @Abel Cajaraville Capote ,

    Might be a bit late but the AMA currently has a 10GB buffer. The time which the agent can be offline and buffer those logs, relies solely on the Events Per Second that are received. Less events = more time, more events = less time.

    With an estimation of your event size and the events per second, you are able to roughly determine for how long the AMA can handle and outage.

    Additionally, Microsoft is working on a feature to expand the buffer from 10GB to 50GB via an AgentSetting DCR. Unfortunately, it's still in preview and currently not functioning properly.

    You can find the relevant documentation here: Install and Manage the Azure Monitor Agent - Azure Monitor | Microsoft Learn

     

    Kind regards, Alexandros

    1 person found this answer helpful.
    0 comments No comments

  2. Andrew Blumhardt 10,066 Reputation points Microsoft Employee
    2023-01-02T16:25:35.817+00:00

    I am not certain if the AMA for Linux buffer can be configured. Much like the MMA, there is a buffer but the details do not appear to be published. I recommend working with your Microsoft support contacts to request more information if possible.

    https://learn.microsoft.com/en-us/azure/azure-monitor/faq#what-happens-to-application-insight-s-telemetry-when-a-server-or-device-loses-connection-with-azure-

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.