Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security engineer is planning the data ingestion strategy for Microsoft Sentinel. The organization has several on-premises Windows servers and network devices that generate security logs in various formats, including Syslog and Windows Event Logs. These logs must be securely and efficiently ingested into Microsoft Sentinel. What is the most appropriate solution for collecting these diverse on-premises logs?

  1. AMicrosoft Defender for Cloud
  2. BAzure Diagnostic Settings
  3. CAzure Network Watcher
  4. DAzure Monitor Agent (AMA)
Show answer & explanation

Correct answer: D. Azure Monitor Agent (AMA)

The Azure Monitor Agent (AMA) is designed to collect logs from various sources, including Windows Event Logs and Syslog, from both Azure VMs and on-premises servers. It provides a unified, flexible, and secure way to ingest diverse log types into Log Analytics, which powers Microsoft Sentinel.

Why the other options are wrong

  • A. Microsoft Defender for Cloud provides cloud security posture management and workload protection but is not primarily a log collection agent for diverse on-premises systems.
  • B. Azure Diagnostic Settings are used for collecting logs from Azure resources, not on-premises servers or network devices.
  • C. Azure Network Watcher is for monitoring network performance and diagnostics, not for collecting security logs from servers or devices.

Azure Monitor Agent (AMA)

The Azure Monitor Agent (AMA) is a unified agent for collecting monitoring data from guest operating systems of Azure and non-Azure machines and delivering it to Azure Monitor.

  • Replaces older agents (Log Analytics agent).
  • Supports Windows and Linux.
  • Collects logs, metrics, and other monitoring data.

Memory trick: AMA: All Machines, All Logs, All Aboard!

More Mitigate threats using Microsoft Sentinel questions