Microsoft Defender for Cloud Apps
Cloud and workloads

Configure automatic log upload using on-premises Podman on Linux | Microsoft Defender for Cloud Apps

In brief

The article now explains continuous log uploads to Cloud Discovery, uses a clearer setup heading, and clarifies that administrators should consider container, firewall, and syslog changes when checking log status.

What Defender admins need to know

Administrators can use the revised wording to find setup guidance and validate log collection more effectively.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure automatic log upload using Podman

[!INCLUDE Banner for top of topics]

This article describes how to configure automatic log upload for continuous reports in Defender for Cloud Apps using a Podman container on Linux in an on-premises server. Customers usingContinuous reports automatically upload logs from your network firewalls and proxies to Cloud Discovery, providing ongoing visibility into cloud app usage across your organization. Use this Podman-based on-premises deployment when your environment runs RHEL 7.1 or higher must usehigher, which requires Podman instead of Docker for automatic log collection. The configuration tasks include setting up a data source, deploying a log collector container, and verifying that logs are uploaded successfully.

Prerequisites

  • Since Docker and Podman can't coexist on the same machine, make sure to uninstall any Docker installations before running Podman.
  • Make sure that you're signed in to the RHEL machine as user root to deploy Podman

Setup and configurationSet up automatic log upload using Podman

  1. Sign into the Defender portal and select Settings > Cloud Apps > Cloud Discovery > Automatic log upload.

If you're not getting firewall logs from your Podman container, check the following:

  1. Make sure that rsyslog rotates on the log collector.

  2. If you've made changes,changed the container configuration or firewall and syslog settings, wait a couple of hours and run the following command to see if anything'swhether the log status changed:

    podman logs <container name>