HAVING MY SYSLOG SERVER IN AZURE CLOUD FOR ONPREM MIRAKI

AO 20 Reputation points
2024-01-31T20:50:53.22+00:00

This article https://learn.microsoft.com/en-us/azure/sentinel/connect-syslog describes the collection of syslog from linus base devices like my Miraki devices. However, the current architecture requires the use of a VM on-prem which will allow the log analytic agent forward the events over TCP443 to sentinel. is there an approach that allows me to have my syslog collecting server within Azure in the cloud as I intend to migrate from having an on-prem presence?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,129 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
976 questions
{count} votes

Accepted answer
  1. Anonymous
    2024-01-31T21:22:34.2366667+00:00

    There's nothing blocking you from deploying an Ubuntu Azure VM that acts as your syslog collector and forwarder. There's a sample deployment script in this articlehttps://learn.microsoft.com/en-us/azure/sentinel/connect-log-forwarder?tabs=rsyslogAlternatively, if you can deploy the Azure Monitor agent to your devices, you can use Azure Monitor syslog support to act as an integration point with Sentinel. https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-syslog

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful