Thank you for your post!
I understand that you're using the Log Analytics agent to collect data from Microsoft Defender for Cloud, and when adjusting the number of events collected to help reduce your overall volume, you're running into some issues. To ensure I fully understand your issue and hopefully help point you in the right direction, I'll share a summary along with my findings below.
Summary:
- You're using the Log Analytics Agent to collect and store data in a Log Analytics workspace.
- Initially, you went to your Microsoft Sentinel Data Connectors page, specifically the
Security Events via Legacy Agent
connector. Within the Connector page you noticed the setting is set to "none" and a message directing you to change the tier within Microsoft Defender for Cloud. - After navigating to Microsoft Defender for Cloud to change the Environmental Settings for your selected Subscription, you noticed the drop-down menu greyed out with "All Events" selected and another informational message.
Findings:
- From my understanding, when it comes to the message - "Available for premium tier only", this should be specifically referring to your Log Analytics workspace. For more info.
- When changing the Security Event options within my tenant, I wasn't able to fully reproduce your issue since I enabled this from my Sentinel Connector Page. However, to further troubleshoot your issue, can you try to change / set your security event options at the workspace level?
Note: Navigating to the workspace itself should provide you with a more detailed message specific to that workspace as shown in my screenshot below.
Additional Links:
- Windows security event options for the Log Analytics agent
- Setting the security event option at the workspace level
- Change pricing tier for Log Analytics workspace
I hope this helps! If you're still having issues and would like to work with our support team through a one-time free technical support request, please let me know.
Thank you for your time and patience throughout this issue.
If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.