Has anyone experienced logs being cleared when Azure Arc is updated?

Deimling, Alex 0 Reputation points
2024-08-22T16:49:49.86+00:00

Hello All,

Coinciding with an Azure Arc update we had received an alert that logs were cleared as well. Our client security team explained they have seen this case in other clients as well. But, I cannot find documentation to be 100%, as log clearing can also be an IOC.

I am sure this is a false positive of any malicious intent, but thought id share if anyone else has experienced this?

C:\Program Files\WindowsAdminCenter\PowerShellModules\Microsoft.WindowsAdminCenter.Configuration\Microsoft.WindowsAdminCenter.Configuration.psm1 is the script that was ran which was around same time as Arc update.

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
435 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.