JTCyberTech / Cybersecurity-Home-Labs

5 stars 1 forks source link

Part 2: Configuration of Sentinel Diagnostic Settings #45

Open JTCyberTech opened 11 months ago

JTCyberTech commented 11 months ago

Configuration of Sentinel Diagnostic Settings

The Sentinel is deployed but we have encountered an error related to data connector that require a license. But everything else should be setup correctly.

Resource Groups



- Click on the resource group that we just create. "SEC-Monitoring"



- Click on the Log Analytics Workspace. "SEC-Monitoring".



- Scroll down on the left side bar and click on "Diagnostic settings".



- Add a new diagnostic setting by clicking on the "Add diagnostic setting".



- Apply these information: - Diagnostic setting name: Sentinel . - For Logs, check the box "allLogs". - For Metrics, check the box "AllMetrics". - For Destination details: - Check the box for "Send to Log Analytics workspace". - For Log Analytics workspace, select "SEC-Monitoring". - Confirm by clicking on "Save".