Azure Sentinel Lab Series | Ingest Ubiquiti logs into Azure Sentinel | EP7

  Рет қаралды 3,659

TeachJing

TeachJing

Күн бұрын

Пікірлер: 14
@TeachJing
@TeachJing 3 жыл бұрын
I don’t think I included the one-liner script to install the log analytics agent. It’s in the description!
@peacejon2019
@peacejon2019 2 жыл бұрын
Can you do a vid of ingesting SQL server logs to sentinel?
@gerryvs69
@gerryvs69 2 жыл бұрын
Nice video ! Do you have any idea for the firewall log-entries why the DROP/REJECT/ALLOW is not listed ? That would make it lots more usefull to troubleshoot.
@brianbrotschi685
@brianbrotschi685 2 жыл бұрын
unable to login into directory named after workspace ID. All seemed to work on my first install, then I needed to change tenants and rebuild the Linux host running the OMS Agent. After running the install package using the recommended script (from this post), I ran into a permissions issue when attempting to navigate to folder /etc/opt/microsoft/omsagent/workspace_id/conf/ location. I am using the sudo cd command, but getting a permissions denied response. I notice that the folder has the following permissions drwxr-x--- 4 omsagent omiusers 4096 Oct 22 22:59 workspace_id Andy idea on how I overcome what appears to be a folder permissions issue ?
@SS-hc6sp
@SS-hc6sp 2 жыл бұрын
Great video. I was able to get everything wired up accordingly. The workbook doesn't come over by default - this may be due to some change on the MS side, but was able to add the json from GitHub as a custom workbook manually, and it opened up. Interestingly, it's not showing me top URLs or resolving host names for local workstations, and a basic query shows events with where isnotempty(DnsQuery) returns no records. I'm pulling a lot of data in however, particularly from APs. I'm doing this from a UDMP, so not sure if that's responsible for breaking things. I changed the logs on the UDMP from default to verbose to see if that gets me the fields I'm after. Also, I'm not clear how I can get this data over to Defender for Cloud Apps. There's a method to do custom ingestion, but it doesn't seem capable of reusing the feed from sentinel. I think it would be better(?) to get the data into cloud apps and have that push its data over to sentinel, perhaps. Any experience with UDMP or Cloud Apps?
@divyasreeveluri5263
@divyasreeveluri5263 2 жыл бұрын
Can you explain how the alerts flow will be
@aidenryan1756
@aidenryan1756 2 жыл бұрын
Great Video, Thanks
@waqarahmad3547
@waqarahmad3547 3 жыл бұрын
Bro good going! Very informative thank you so much for sharing your knowledge.
@TeachJing
@TeachJing 3 жыл бұрын
Your welcome!
@brianbrotschi685
@brianbrotschi685 3 жыл бұрын
thanks for taking the time to document these steps. Did you need to create a specific firewall rule (e.g. TCP 80 & 443 outbound allow & log) on the Ubiquity system to create the syslog contents ? Or will the "Remote Logging" options shown in the Ubiquiti controller config suffice ?
@TeachJing
@TeachJing 3 жыл бұрын
Should suffice. And it uses the custom port you configure. If you got a firewall setup with multiple vlan or networks than you do have to configure some firewall rules. But if you have a standard network than it should flow fine unless this syslog collector is in the cloud or something.
@brianbrotschi685
@brianbrotschi685 3 жыл бұрын
@@TeachJing OK, thanks. I will remove the firewall rule (HTTP & HTTPS, outbound, allow, log) which I have in place, as it is generating lots of syslog events.
@rahul53403
@rahul53403 2 жыл бұрын
Nice👍
@sconnell194
@sconnell194 3 жыл бұрын
👍
Как мы играем в игры 😂
00:20
МЯТНАЯ ФАНТА
Рет қаралды 3,3 МЛН
Will A Guitar Boat Hold My Weight?
00:20
MrBeast
Рет қаралды 263 МЛН
Containers vs VMs: What's the difference?
8:08
IBM Technology
Рет қаралды 762 М.
What's the BEST home server operating system?
17:35
Christian Lempa
Рет қаралды 661 М.
Postgres just got even faster
26:42
Hussein Nasser
Рет қаралды 32 М.
18 Weird and Wonderful ways I use Docker
26:18
NetworkChuck
Рет қаралды 220 М.
The GIGA JUKE is dead.
28:02
Mend It Mark
Рет қаралды 68 М.