Not receiving Windows WMI logs on Azure Sentinel

Gaurav Mourya 1 Reputation point
2021-06-22T13:50:44.833+00:00

We have a High priority Task related to WMI (Windows Management Instrumentation) logs ingestion to Azure Sentinel for a Client. We are facing some issues while ingesting WMI Logs to Azure Sentinel. We have installed the Microsoft Monitoring Agent on the machine and trying to ingest logs by adding the following Agents Configurations in Log Analytics Workspace

  • Microsoft-Windows-WMI-Activity/Operational
  • Microsoft-Windows-WMI-Activity/Trace
  • SmbWmiAnalytic
  • wmi
  • WMI-Activity

We have referred to https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-to-go-part2-integrating-a-basic-windows-lab-via/ba-p/1742165 guide to implement the process.
We are receiving WMI Events on Windows Event Viewer but these events are not flowing to Log Analytics Workspace.

We have a good relation with the client, so need to resolve this on an urgent basis because to maintain our relationship.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,065 questions
{count} votes