Additional logs for Azure VM filebeat module in my operating system

Carolina Zamisnicu 316 Reputation points
2021-06-15T10:40:46.857+00:00

Hello,

I have a question regarding the logs received from Azure. Is there any possibility that I might receive other logs that can be useful for an analyst besides the internal logs that I'm receiving from my VM (the linux kind of logs that I'm receiving due to the Azure filebeat module that I installed on my VM)?
For example, if Windows is creating other logs for my VM while the internal ingestion of data is being made in the VM environment.

If there are any other logs, besides that ones that I ingest in Elastic from my VM, how can I collect them? Should I use a separate storage account for them?

I wonder that if there are other logs they might be interesting for me (from an analyst perspective) and I should also take them into consideration.
Thank you!

Windows development | Windows API - Win32
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.