how to Deploy Sysmon To Receive Logs In Azure Sentinel?

Shital Khatri - AzureAdmin 101 Reputation points
2022-01-05T05:28:24.213+00:00

how to Deploy Sysmon To Receive Logs In Azure Sentinel?

Microsoft Security Microsoft Sentinel
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,311 Reputation points Microsoft Employee
    2022-01-05T12:39:42.477+00:00

    @Shital Khatri - AzureAdmin Thanks for reaching out.

    Sysmon tool can be deployed by using group policy if you have a local AD setup, if you manage them using Intune, You can use Intune to setup the Sysmon on devices.
    Followed by MMA agent which will pick all these information from the machine and send it upto the Log analytic workspace where Sentinel is enabled.

    A more detailed approach with step by step instructions can be found at : https://m365internals.com/2021/05/17/how-to-deploy-sysmon-and-mma-agent-to-receive-logs-in-azure-sentinel/

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.