Sentinel Reconfiguration Testing

Onyx36 0 Reputation points
2023-11-01T15:32:34.67+00:00

Need the below tested with results:

On machines installed with both legacy and new agents - remove the legacy agent (breaking Sentinel connection)

Reconfigure Sentinel to see if Data Collection Rules are automatically recreated.

Need assistance with this as I am not versed in Sentinel.

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,051 Reputation points Microsoft Employee
    2023-11-06T13:11:58.91+00:00

    For Windows Security Events you will use the "Windows Security Events via AMA" connector page. From there you can create Windows Security Event DCR rules (it will not be created automatically). Though, any VMs or Arc systems in scope for the DCR rule will get the AMA extension deployed (if not already applied by policy).

    These rules created from the connector page may appear to be blank or empty when viewing from the DRC page. That is due to the template not matching the UI criteria. You can verify event collection in the SecurityEvents table. Additional DCR instructions provided below.

    https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-collection-rule-azure-monitor-agent?tabs=portal


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.