Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A company is integrating Microsoft Sentinel with its existing security tools. The security team needs to ingest security events from an on-premises Linux server that hosts critical applications. The server cannot directly connect to Azure over the internet due to strict network security policies. Which component should be used to securely forward these logs to Microsoft Sentinel?
- ALog Analytics Gateway
- BAzure Private Link
- CAzure Network Watcher
- DAzure Arc-enabled servers
Show answer & explanationAnswer & explanation
Correct answer: A. Log Analytics Gateway
The Log Analytics Gateway acts as a proxy, allowing on-premises servers that cannot directly connect to Azure Log Analytics (which underpins Sentinel) to send their logs securely through a single point of egress.
Why the other options are wrong
- B. Azure Private Link provides private connectivity to Azure services but typically requires direct network connectivity or VPN/ExpressRoute, which the scenario explicitly restricts for the server.
- C. Azure Network Watcher is for network monitoring and diagnostics, not for log ingestion.
- D. Azure Arc-enabled servers allow managing on-premises servers from Azure, but don't directly solve the log forwarding issue under strict network constraints without a gateway.
Log Analytics Gateway
A Log Analytics Gateway is an HTTP forward proxy that allows on-premises machines to send log data to Azure Log Analytics workspaces (and thus Microsoft Sentinel) from behind a firewall.
- Acts as a proxy for log ingestion.
- Useful for isolated on-premises networks.
- Requires outgoing HTTPS connectivity to Azure.
Memory trick: Isolated servers need a 'Gateway' to send their secrets to the cloud.