Monitoring Agent: On-Prem server Windows Security Logs lookup?

RT-7199 471 Reputation points
2023-03-27T00:15:07.6433333+00:00

So at some point we added monitoring agent to all our on-prem servers and I picked one of our Domain Controllers name to see which tables has that name and it listed below.

search 'DC.ab.xyz.com'

| distinct $table

Update

ComputerGroup

AzureActivity

Operation

UpdateSummary

ProtectionStatus

SecurityRecommendation

NetworkMonitoring

Event

SecurityAlert

Perf

InsightsMetrics

VMConnection

Heartbeat

I am looking for windows security logs to be in log analytics workspace and from what I know they should be coming to SecurityEvent table, which for us is empty.

The Event table also has only these event logs, and they are also not consistent

Event

| distinct EventLog

System

Application

Microsoft-Windows-TerminalServices-LocalSessionManager/Operational

Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin

Microsoft-FSLogix-Apps/Admin

What updates/changes do we need to do to include security logs from windows servers.

User's image

User's image

In legacy agent i see these options selected
User's image

and I can't seem to find relevant security log
User's image

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,798 questions
{count} votes

Accepted answer
  1. AnuragSingh-MSFT 19,691 Reputation points
    2023-03-27T09:11:41.7033333+00:00

    @RT-7199 , Thank you for the detailed information in the question.

    Based on the information, you have added "Microsoft Monitoring Agent" (also know as MMA, Log Analytics Agent or LA agent). It is by design that you cannot see the security event in the LA workspace when using this agent. See the Important section in the following link for more details - Configure Windows event logs.

    Therefore, to collect the security event logs, you must use Microsoft Defender for Cloud or Microsoft Sentinel

    Alternatively, you can migrate the monitoring from this agent to newer Azure Monitor Agent where you can configure Data collection rules for collecting security event logs. Note that the Microsoft Monitoring Agent (LA Agent) will be retired by August 31, 2024. Therefore, I would recommend to start planning the migration from legacy MMA to newer AMA. For more details, see Migrate to Azure Monitor Agent from Log Analytics agent

    Please let me know if you have any questions.

    If the aswer did not help, please add more context/followup question for it, and we will help you out, else please click Accept answer so that it can help others in the community looking for help on similar topics.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful