Share via

Postgre SQL installed on Linux server

Anonymous
2023-10-10T04:42:50.53+00:00

Postgre SQL is installed on the Linux server, and the logs from the Linux server are landing into Sentinel, but in the Linux server, the customer has a schema, and the schema has a table, how to integrate the table logs into Sentinel.

Azure Database for PostgreSQL
Microsoft Security | Microsoft Sentinel
0 comments No comments

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,396 Reputation points Microsoft Employee Moderator
    2023-10-10T21:47:29.89+00:00

    @Anonymous

    Based on the information you provided, it sounds like the best option for your scenario would be to use the PostgreSQL Events connector for Sentinel to integrate the table logs from the Linux server. https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/postgresql-events

    Once you have configured PostgreSQL to write logs to files, you can use the connector to ingest the logs into Sentinel and then query the logs.

    Let me know if this seems to suit your scenario.

    If the information addressed your request, please Accept the answer. This will help us and improve searchability for others in the community who may be researching similar information. Otherwise let me know if you have further questions.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.