Azure Sentinel (IIS, SQL, Syslog server)

Eduards 791 Reputation points
2020-12-28T11:40:42.47+00:00

Hello,

I am new to Azure Sentinel - so i need to implement this solution.

So basically i need to collect logs from Active Directory, IIS, SQL Server make SYSLOG (linux) server which will collect Windows Firewall Logs and then send it's to Syslog server which will send it to azure sentinel.

Ok. So For AD, IIS, SQL on-premise server what i need to do i install MMA agent and connect to my Azure Sentinel workspace.
And how i figured out that i need to select "Common" option.

51577-image.png

But what about IIS, SQL server logs? - have i need to do some additional configuration to receive logs?

Also what are most common queries for this servers to create or use?

Also how could i now that Azure Sentinel is trial? And where to see when it will be over?

Or i need to schedule log collecting deadline ? - is this possible?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 35,036 Reputation points Microsoft Employee
    2020-12-28T21:28:52.673+00:00

1 additional answer

Sort by: Most helpful
  1. Eduards 791 Reputation points
    2021-01-03T09:02:43.683+00:00

    Also i got question about DNS logs.

    I turned DNS logging on. Also enabled on-prem DNS server debug logging.

    But Azure Sentinel doesnt receive Event ID 257 and logs from debug

    0 comments No comments