OMS Agent (CEF) w/ Private Link

Patrick M. Williams 1 Reputation point
2022-06-15T15:06:17.027+00:00

Is it possible to send CEF logs over Private Link to workspace my Sentinel uses? I currently have a log forwarder (OMS Agent) in Azure for my remote firewalls and one at my HQ (where my ExpressRoute is located). I want to send the logs at the HQ over ExpressRoute via Private link. I already send Arc logs over private link, and I am in the process of setting up AMPLS for my servers to send logs to Sentinel. I also might change my remote firewalls to send logs via IPSec back to the HQ's CEF forwarder(also OMS Agent), instead of having them send over the internet to my Azure CEF forwarder.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
606 questions
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
274 questions
{count} votes