Тёмный

Microsoft Sentinel Ingest Logs from Linux Machines 

Concepts Work
Подписаться 39 тыс.
Просмотров 1,3 тыс.
50% 1

Опубликовано:

 

17 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 3   
@srikanthk-s6b
@srikanthk-s6b 2 месяца назад
Could you also do a video on how to inject AWS security logs (either from Security hub or CloudTrail) into Sentinel ?
@RichardGailey
@RichardGailey 3 месяца назад
Awesome video series as always. On the DCR Rules, is there a way to approximate the size of the logs that will be ingested vs the old MMA methos (grabs everything) when selecting Common Events vs All Events. Also, is selecting just Common Events good enough from a security monitoring point of view, or are some other logs covered via the All Events (ingesting everything) that the Common Events wouldn't cover. If that is the case, are we able to select the common Events option, but also include some other type of events we want ingested via additional X-Path queries. Just asking as I know if the past we had an issue where logs that we were ingesting suddenly spiked to over $100K a month from previous $10K and really don't want to run in to an issue like that again
@ConceptsWork
@ConceptsWork 3 месяца назад
There is a dual data ingestion issue with syslog and CEF, we will cover that in a lot more detail. Regarding data ingestion cost you need to make queries to data ingestion cost, I mean you have calculate the size of data ingestion with tables and apply a filter of _isBillable==True.
Далее
Human vs Jet Engine
00:19
Просмотров 21 млн
Microsoft Sentinel Incident Investigation
33:12
Просмотров 1,1 тыс.
10 - Log-Server (rsyslog)
32:11
Просмотров 4,4 тыс.
Azure Sentinel For Beginners (2024)
1:41:45
Просмотров 3,5 тыс.
Setup Microsoft Sentinel | Tutorial
15:15
Просмотров 1,9 тыс.