wwlpublish Connect syslog data sources to Microsoft Sentinel - Training
- This module covers configuring
Azure Monitor Agent
forSyslog data collection on Linux
, includinginstallation
,setup
, andverification
ofSyslog logs
in MicrosoftSentinel
. Learners will be able to describe Data CollectionRules
,install
and configure the necessary extensions, and createKQL parsers
for analyzing Syslog data.
‣
Introduction
‣
Plan for syslog data collection
‣
Collect data from Linux-based sources using syslog
‣
Configure the Data Collection Rule for Syslog Data Sources
‣
Parse syslog data with KQL
‣
Knowledge check
‣