Nsg Log to Sentinel

Rohit 1 Reputation point
2020-07-20T07:14:04.533+00:00

Hello,

Can any one provide me the exact process/Docs/link for how to enable Azure Firewall(NSG) to Sentinel.
Or how to see the (Azure Firewall) NSG logs in Sentinel.

Thanks
Rohit

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
589 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Leon Laude 85,701 Reputation points
    2020-07-20T08:19:26.307+00:00

    Hi,

    Something here might help:

    Azure Sentinel: Collecting logs from Microsoft Services and Applications
    https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-collecting-logs-from-microsoft-services-and/ba-p/792669

    Map data types with Azure Sentinel connection options
    https://learn.microsoft.com/en-us/azure/sentinel/connect-data-sources#map-data-types-with-azure-sentinel-connection-options

    Best regards,
    Leon

    0 comments No comments

  2. Ken Golitin 21 Reputation points
    2020-07-20T08:50:42.203+00:00

    Hi,

    Enable NSG Flow logging if you want this part as well, be careful of the related storage cost
    https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics
    https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-portal

    Turn on Diagnostics logs on all NSG
    Under MONITORING, select Diagnostics logs, and then select Turn on diagnostics.
    https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log

    Collect logs for sentinel following the paragraph "How can I collect from a supported Azure source?"
    https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-collecting-logs-from-microsoft-services-and/ba-p/792669

    let me know if everything fine and mark this as answered in case it solve your issue please.
    Thank you.
    Ken

    0 comments No comments