I have a scenario at my work where i need to send logs from multiple resources on azure to single log analytics workspace for compliance purpose and then ingest the same logs to Azure Sentinel workspace for SIEM services, i however cannot enable Azure Sentinel on the first workspace, any leads or solutions please.
sending logs to multiple Azure Log analytics workspaces
1.6k Views Asked by kay At
1
There are 1 best solutions below
Related Questions in AZURE
- How to update to the latest external Git in Azure Web App?
- I need an azure product that executes my intensive ffmpeg command then dies, and i only get charged for the delta. Any Tips?
- Inject AsyncCollector into a service
- mutual tls authentication between app service and function app
- Azure Application Insights Not Displaying Custom Logs for Azure Functions with .NET 8
- Application settings for production deployment slot in Azure App Services
- Encountered an error (ServiceUnavailable) from host runtime on Azure Function App
- Implementing Incremental consent when using both application and delegated permissions
- Invalid format for email address in WordPress on Azure app service
- Producer Batching Service Bus Vs Kafka
- Integrating Angular External IP with ClusterIP of .NET microservices on AKS
- Difficulty creating a data pipeline with Fabric Datafactory using REST
- Azure Batch for Excel VBA
- How to authenticate only Local and Guest users in Azure AD B2C and add custom claims in token?
- Azure Scale Sets and Parallel Jobs
Related Questions in AZURE-LOG-ANALYTICS
- Is there a way to view traffic logs for Azure Storage for connections that got blocked by Firewall settings from Networking pane?
- Not able to view the logs for hosted WebApp in Azure
- Azure DataBricks - Looking to query "workflows" related logs in Log Analytics (ie Name, CreatedBy, RecentRuns, Status, StartTime, Job)
- Sent the Postgresql query result to Log Analytics workspace to create custom metric in Azure Monitor
- Databricks Log Analytics Logs missing log
- Azure hide not mine logs - see only my logs
- KQL - How to enrich an event by matching an IP address to an IP range from a Sentinel Watchlist?
- How to Plot Pre-Averaged Time Series Data in KQL Without Using Summarize?
- Logic Apps: Run query and visualize results Html Table displayed in Email
- How can I use kusto to show which permissions are being used by which users on the data plane
- Sending log analytics workspace logs to Sentinel
- Unable to receive metrics on Log Analytics workspace from a Windows VM in Azure
- Azure Heartbeat Table: _ResourceId is blank
- Log Analytics Workspace / Azure Watchlist: KQL Filtering on datetime
- How can I keep on logging after retirement of instrumentationkey and classic application insights?
Related Questions in AZURE-SENTINEL
- Logic Apps: How to use create a new watchlist with data (raw content) module
- Issue with my Logic app - Send-email-with-formatted-incident-report
- KQL - How to enrich an event by matching an IP address to an IP range from a Sentinel Watchlist?
- Place KQL results into an indexable array
- Why does the ClientAppId column in the OfficeActivity table have guids that don't relate back to Enterprise Applications / App Registrations?
- KQL: bag unpack json into single row
- Sending log analytics workspace logs to Sentinel
- Need help to understand if azure sentinel data connection solution is being built correctly
- How to understand Microsoft Entra application required for log ingestion API
- Trying to parse non-uniform JSON arrays with KQL in Sentinel
- No attribute while using yamldecode in Terraform code
- Logic Apps / MS Graph API: Quarantine an email autonomously
- Azure Activity: Storage account access key retrieval
- KQL diferent tables
- How to change/upgrade the microsoft azure function app plan from consumption to premium under microsoft sentinel using GCP Data Connnector?
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular # Hahtags
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
Firstly I think your best option is to put everything into one log analytics workspace with the longer retention period but lets say that is not at all possible.
I can see 2 options here: The easiest is probably to set up 2 diagnostic settings on each resource which points to the separate log analytics work spaces.
A much harder option would be to use continuous export into Azure Storage (which could be all you need to do) or event hub and then process this back into log analytics with an Azure function.
Last comments would be that your going to be paying for the data ingest twice no matter what is done here which will at least double your costs for the lower retention time.