Microsoft Defender for Cloud Apps
Cloud and workloads

Configure automatic log upload for continuous reports in Microsoft Defender for Cloud Apps

In brief

The page title now identifies Defender for Cloud Apps, removal steps explicitly refer to the collector container, and the deployment section directs administrators to choose a guide for their platform.

What Defender admins need to know

Administrators can use clearer instructions when removing collector containers and selecting the appropriate deployment guide.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure automatic log upload for Defender for Cloud Apps continuous reports

Log collectors enable you to easily automate log upload from your network. The log collector runs on your network and receives logs over Syslog or FTP. Each log is automatically processed, compressed, and transmitted to the portal. FTP logs are uploaded to Microsoft Defender for Cloud Apps after the file finished the FTP transfer to the Log Collector. For Syslog, the Log Collector writes the received logs to the disk. Then the collector uploads the file to Defender for Cloud Apps when the file size is larger than 40 KB.

To install a new log collector version, you must stop the log collector, remove the current image, and then install the new one.

Related content

The Log Collector supports the Container deployment mode. Choose the container deployment guide for your platform: