Microsoft Sentinel
Cloud and workloads

Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent

In brief

The article now clarifies required permissions, agents, and log forwarder prerequisites and documents setup through either the Azure or Defender portal or the Logs Ingestion API.

What Defender admins need to know

Administrators have clearer options for installing the Azure Monitor Agent and creating and associating a data collection rule.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent

This article shows you how to use the Syslog via AMA and Common Event Format (CEF) via AMA connectors to filter and ingest syslog and CEF messages from Linux machines, network devices, and security appliances. Before you begin, reviewmake sure you have the Prerequisites section for required permissions, agents, and log forwarder setup.setup as described in the Prerequisites. To learn more about these data connectors, see Syslog and Common Event Format (CEF) via AMA connectors for Microsoft Sentinel.

Azure or Defender portal

Use the Azure or Defender portal to create a data collection rule (DCR) and install the Azure Monitor Agent on your log forwarder.

Create data collection rule (DCR)

To get started, open either the Syslog via AMA or Common Event Format (CEF) via AMA data connector in Microsoft Sentinel and create a data collection rule (DCR).

Logs Ingestion API

Use the Logs Ingestion API to install the Azure Monitor Agent, create the data collection rule, and associate the rule with your log forwarder.

Install the Azure Monitor Agent

Follow the appropriate instructions from the Azure Monitor documentation to install the Azure Monitor Agent on your log forwarder. Remember to use the instructions for Linux, not for Windows.