Microsoft Defender for Cloud
Cloud and workloads

Use a Custom Data Collection Rule for Defender for Servers ingestion

In brief

The article now includes steps for creating a custom data collection rule in the Azure portal and revises guidance for using Azure Policy to create and assign DCRs across subscriptions. Metadata and a next-step link were also updated or removed.

What Defender admins need to know

Administrators get clearer guidance for configuring custom DCRs and managing DCR assignments at scale.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create a DCR

To create a custom DCR in the Azure portal, follow these steps:

  1. Sign into the Azure portal.

  2. Go to ▸ MonitorSettingsData Collection Rules+ Create.

Deploy using Azure Policy

For large environments,If you canmanage many subscriptions, use Azure Policy to automatically create and assign Data Collection Rules (DCRs) forDCRs at scale. The Deploy AMA DCR for Security Events collection policy initiative applies security eventsevent collection rules across multiple subscriptions by using the Deploy AMA DCR for Security Events collection initiative.your environment.

Related content

[!div class="nextstepaction"] Use the data ingestion benefit in Microsoft Defender for Cloud