Connecting your first data source
Before we dig into the details of the Microsoft Sentinel data connectors (see Chapter 3, Managing and Collecting Data), we will review how Log Analytics enables connectivity to a range of different sources to receive data to store and analyze. Some of the data source options include the following:
- Application and OS diagnostics
- Virtual machine log data
- Azure storage account logs
- Azure Activity log
- Other Azure resources
In this section, we will show you how you can enable log collection from Azure virtual machines.
Obtaining information from Azure virtual machines
To have the virtual machines (VMs) populate a Log Analytics workspace, they need to be connected to it. This is done from the Log Analytics workspace Overview page.
There are two different ways to get to this page. First, you can select Log Analytics in the Azure portal navigation menu and then select the appropriate workspace. The second, and perhaps...