Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A company is migrating its on-premises security logs to Microsoft Sentinel. They need to ingest logs from Windows servers, Linux servers, and network devices. The solution must ensure secure and efficient data collection without requiring direct internet access from the on-premises devices to Azure. Which component should be centrally deployed on-premises to facilitate this ingestion?
- ALog Analytics gateway
- BAzure Arc-enabled servers
- CAzure Firewall
- DAzure Network Watcher
Show answer & explanationAnswer & explanation
Correct answer: A. Log Analytics gateway
The Log Analytics gateway acts as a proxy for agents (like AMA) to send logs to Azure Monitor (and thus Sentinel) when direct internet access is restricted. It centralizes log collection from multiple on-premises sources.
Why the other options are wrong
- B. Azure Arc-enabled servers extend Azure management to on-premises servers but don't primarily serve as a log ingestion proxy.
- C. Azure Firewall is a cloud-native firewall service in Azure, not an on-premises log collection component.
- D. Azure Network Watcher is for network monitoring and diagnostics within Azure, not for on-premises log ingestion.
Log Analytics Gateway
A Log Analytics gateway acts as a proxy that forwards data from agents to Azure Monitor when agents cannot directly connect to Azure Monitor due to network restrictions.
- Centralizes log collection from multiple agents.
- Supports Windows and Linux agents.
- Requires outgoing HTTPS (port 443) to Azure Monitor endpoints.
Memory trick: Gateway Guards On-Premises Logs to Cloud