How can I connect GNS3 network to Microsoft Sentinel?

Miloslav Šťastný 21 Reputation points
2022-05-13T18:17:26.987+00:00

Hello,
I am trying to use a GNS3 network as input data to Microsoft Sentinel. My GNS3 server with GNS3 network is running on a virtual Linux machine, so I can monitor it with Syslog connector successfully. However I am unable to detect anything from the GNS3 network. Any idead how to solve this? I would be grategul for any answer.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
Microsoft Security | Microsoft Sentinel
{count} votes

Answer accepted by question author
  1. David Broggy 6,616 Reputation points MVP Volunteer Moderator
    2022-05-26T04:32:21.01+00:00

    Hi @Miloslav Šťastný
    Microsoft Sentinel expects that any servers you want to monitor are running their monitoring agent.
    In the Azure portal, type ‘log analytics workspace’ in the top search box.
    Open the Log Analytics Workspace that is associated with your Sentinel configuration.
    Select the ‘Agents’ section and go to the Linux tab.
    You will see a curl command you can use to download and install the Azure Monitor (OMS) agent.
    Once this agent is installed you should have logs showing up in Sentinel as described in the Windows Security Events connector configuration (in the Sentinel > Connectors UI)


1 additional answer

Sort by: Most helpful
  1. Miloslav Šťastný 21 Reputation points
    2022-05-26T11:58:59.337+00:00

    Thank you for your help, I have eventually solved it.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.