How to take the Network Security Group(NSG) logs to Azure Sentinel

Anonymous
2020-07-18T19:15:54.85+00:00

Hello,

I have Azure Sentinel, Kindly suggest the steps how to forward the NSG(Azure Firewall) logs to Sentinel.

Regards,
Chandan Prajapati

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
580 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
999 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 34,626 Reputation points Microsoft Employee
    2020-07-30T22:56:23.383+00:00

    Hi @AnonUser,

    It looks like someone asked this same question here.

    As shared in that post, here is the guide for enabling NSG Flow logging.

    You would turn on diagnostics logs on all Network Security Groups. To do this, go to Monitoring > select Diagnostics logs > select "Turn on diagnostics."

    https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log

    Then collect logs for sentinel ("How can I collect from a supported Azure source?"):

    https://learn.microsoft.com/en-us/azure/sentinel/connect-data-sources#map-data-types-with-azure-sentinel-connection-options

    Let me know if this is what you are looking for or if you need additional information.

    1 person found this answer helpful.