Everything You Ever Wanted to Know About Using the New Azure Monitor Agent with Microsoft Sentinel

  Рет қаралды 7,589

Microsoft Security Community

Microsoft Security Community

Күн бұрын

Пікірлер: 13
@AquibQureshi
@AquibQureshi 3 жыл бұрын
thanks Team, a very good explanation about the AMA and supported scenario
@Ruchikun
@Ruchikun 2 жыл бұрын
[02:55] Contents [04:50] Why a new agent ? [09:00] Azure Monitor Agent Supportability [10:00] Azure arc as a requirement for non-azure machines [11:26] Azure arc (what is...) [14:15] Feature gap analysis between LAG and AMA [16:50] Microsoft Sentinel collection with AMA [19:55] Security Events before and now [26:16] Windows Forwarded Events [32:27] Data collection Rules [38:20] Deploying Azure Arc and AMA at scale [45:58] Should I migrate now? [48:33] Useful resources [48:58] Questions
@tijubrain1
@tijubrain1 3 жыл бұрын
Awesome presentation!
@mmiltenburg
@mmiltenburg 2 жыл бұрын
Great overview. Thanks very much!
@matthewfranklin7541
@matthewfranklin7541 3 жыл бұрын
Many thanks, a very useful presentation!
@debarghyadasgupta1931
@debarghyadasgupta1931 3 жыл бұрын
Loved it ❤️
@mmkmur1
@mmkmur1 3 жыл бұрын
Thank you! Very informative ! One Q: When will the workbook be available ?
@simple-security
@simple-security 2 жыл бұрын
I've seen no updates on how the AMA agent will work with 'regular' windows workstations (non-servers). All I can find is a link to download the AMA agent (after creating a collection rule) but no details on configuring the agent for a specific workspace, etc. I see that workstations will need to be domain connected and synced with Azure AD. Will WEC be a requirement for non-domain connected workstations?
@1213xyz
@1213xyz Жыл бұрын
As this webinar was recorded some time ago, I am wondering stuff mentioned in this entire video, are they still valid? Like Windows DNS/Firewall, Syslog, CEF or Sysmon not supported by AMA. Is this still valid?
@b2secops
@b2secops 2 жыл бұрын
Hi, thanks for the informative video. Just need some clarification around the two connectors you mentioned. Firstly, what is the difference between the Windows Forwarded Events and Windows Security Events via AMA collectors? I see you used Windows forwarded events for getting events from your DC to Sentinel, can the Windows Security Events also be used to get events from your DC? or is it that it collects 'Security events' only. Thank you
@Ruchikun
@Ruchikun 2 жыл бұрын
It's a shame some of these high level architectural overviews (images) are not to be found on your website. Would help to understand it
@MicrosoftSecurityCommunity
@MicrosoftSecurityCommunity 2 жыл бұрын
Hi Ken, All of the presentations from the Microsoft Security Community webinars can be found at aka.ms/SecurityCommunity The link is located in the webinars and recordings section. Thank you for watching!
@rafaelruales6871
@rafaelruales6871 3 жыл бұрын
thanks
Create Your Own Microsoft Sentinel Solutions
54:38
Microsoft Security Community
Рет қаралды 3,6 М.
Announcing the New Microsoft Sentinel Incident Investigation Experience!
49:13
Microsoft Security Community
Рет қаралды 7 М.
Жездуха 42-серия
29:26
Million Show
Рет қаралды 2,6 МЛН
Wednesday VS Enid: Who is The Best Mommy? #shorts
0:14
Troom Oki Toki
Рет қаралды 50 МЛН
Azure Sentinel webinar: Data Collection Scenarios
1:00:29
Microsoft Security Community
Рет қаралды 8 М.
Overview of the SOC Process Framework
51:05
Microsoft Security Community
Рет қаралды 7 М.
Azure Sentinel webinar: Deep Dive on Threat Intelligence
58:04
Microsoft Security Community
Рет қаралды 12 М.
Demystifying Microsoft Defender for Servers
58:58
Microsoft Security Community
Рет қаралды 13 М.
Introduction to Azure Sentinel. Part 1 - Foundations
54:21
Netrix Global
Рет қаралды 12 М.
What's Next in Microsoft Sentinel - March 2022
55:26
Microsoft Security Community
Рет қаралды 10 М.
Azure Sentinel webinar: Threat Hunting (part 1)
59:33
Microsoft Security Community
Рет қаралды 17 М.
Жездуха 42-серия
29:26
Million Show
Рет қаралды 2,6 МЛН