how to send MYSQL audit logs to Sentinel?

Juan Araya 0 Reputation points
2021-10-25T10:30:59.68+00:00

Hi

We have an AWS EC2 instance running a MYSQL DB. We would like to send the MYSQL audit logs(JSON format) to Azure Sentinel. Is it there a connector or process to meet this requirement?

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 37,226 Reputation points Microsoft Employee Moderator
    2021-10-25T20:30:06.213+00:00

    anonymous user
    Thank you for your post!

    Unfortunately, I wasn't able to find any connector available within Azure Sentinel that would allow you to connect a MySQL DB directly to a Sentinel workspace. If you'd like this feature to be implemented, I'd recommend submitting a Feature Request to our Azure Sentinel team via their - Resources GitHub page.

    143593-image.png

    I've also reached out to our Azure Sentinel team to see if there are any other processes/routes you can take to meet your requirement. In the meantime, can you share some more details regarding your environment, so I can gain a better understanding of your issue?

    • How're you getting these logs?
    • Are these logs stored within your AWS VM or within Azure?
    • Are you using any other security features such as Azure Security Center with your AWS or MYSQL instance?

    Any additional information would be greatly appreciated!

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.