Share via

Configure Log Analytics Agent - Log Level Defender for Cloud

Trandum, Sindre 20 Reputation points
Jul 3, 2023, 12:04 PM

Hi!

We are using Log Analytics Agents to collect and store date in a Log Analytics workspace. I wanted to test adjusting the log levels for security events. Current level is "All Events" - I wanted to try to reduce this, as we see a lot of informational events (8002 AppLocker for example) that we would like to stop ingesting to our workspace.

First I went to Sentinel and 'Data connectors' and 'Security Events via Legacy Agent' (Lots of SecurityEvents received). On the connector page the option to change events to stream is greyed out. The settings is set to 'none'. A message reads: "Security Events tier configuration is shared with Microsoft Defender for Cloud and was already configured there for this workspace. Change the tier in Microsoft Defender for Cloud and it will apply for Microsoft Sentinel as well. Note that Security events will be collected once and used in both solutions.".

In Defender for Cloud - Environmental Settings - "Example Subscription" for component Log Analytics agent: Security events: All Events.

After pressing "Edit configuration" there is a drop down menu with the setting All Events selected. The menu is greyed out. A message reads:
To help audit, investigate, and analyze threats, you can collect raw events, logs, and additional security data and save it to your Log Analytics workspace. Select the level of data to store for this workspace. Charges will apply for all settings other than “None”. Available for premium tier only.

Question: Which premium tier is that referencing?

Is it possible to change this setting to reduce the number of SecurityEvents? If we want to exclude a specific EventID - is this possible ?

The Log Analytics Agents will be replaced with AMA, but wanted to change the current settings if possible.

Thanks in advance. -S

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,504 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,251 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,851 Reputation points Microsoft Employee
    Jul 5, 2023, 9:29 PM

    @Trandum, Sindre

    Thank you for your post!

    I understand that you're using the Log Analytics agent to collect data from Microsoft Defender for Cloud, and when adjusting the number of events collected to help reduce your overall volume, you're running into some issues. To ensure I fully understand your issue and hopefully help point you in the right direction, I'll share a summary along with my findings below.

    Summary:

    • You're using the Log Analytics Agent to collect and store data in a Log Analytics workspace.
    • Initially, you went to your Microsoft Sentinel Data Connectors page, specifically the Security Events via Legacy Agent connector. Within the Connector page you noticed the setting is set to "none" and a message directing you to change the tier within Microsoft Defender for Cloud.
    • After navigating to Microsoft Defender for Cloud to change the Environmental Settings for your selected Subscription, you noticed the drop-down menu greyed out with "All Events" selected and another informational message.

    User's image


    Findings:

    • From my understanding, when it comes to the message - "Available for premium tier only", this should be specifically referring to your Log Analytics workspace. For more info.
    • When changing the Security Event options within my tenant, I wasn't able to fully reproduce your issue since I enabled this from my Sentinel Connector Page. However, to further troubleshoot your issue, can you try to change / set your security event options at the workspace level?

    Note: Navigating to the workspace itself should provide you with a more detailed message specific to that workspace as shown in my screenshot below.

    User's image

    Additional Links:

    I hope this helps! If you're still having issues and would like to work with our support team through a one-time free technical support request, please let me know.

    Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.