MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.09k stars 21.13k forks source link

Auditd logging needs clarification #118767

Closed Mrkokoo closed 4 weeks ago

Mrkokoo commented 5 months ago

Documentation states the following:

Does Azure Monitor Agent support auditd logs on Linux or AUOMS? Yes, but you need to onboard to Defender for Cloud (previously Azure Security Center). It's available as an extension to Azure Monitor Agent, which collects Linux auditd logs via AUOMS.

However there are no further configuration steps clarified anywhere in MS docs that I have found that would help us configure auditd logging with the new AMA agent. This is a blocker for migration in some scenarios.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

RamanathanChinnappan-MSFT commented 5 months ago

@Mrkokoo Thanks for your feedback! We will investigate and update as appropriate.

AbbyMSFT commented 4 weeks ago

Opened internal work item to address this issue: https://dev.azure.com/msft-skilling/Content/_workitems/edit/261693

please-close