❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMicrosoftSentinel

Defender P2 for Servers - Sentinel Benefit

3 July 2026 at 04:10

Hi,

We have one subscription that has our Azure Arc enabled machines with the Defender for Cloud P2 applied.

Sentinel is deployed in another subscription. Defender isn't enabled for the log workspace.

My understanding is that if we use the Windows Security Events via AMA to collect events from the Arc Machines, the 500mb benefit won't apply?

I have to enable Data Collection on the Sentinel Workspace in Defender for Cloud, but the sentinel workspace doesn't have those servers reporting to them?

Does that make sense? This is very confusing for me but maybe I'm over complicating it

submitted by /u/DaithiG
[link] [comments]

Syslog Forwarding - Rotation?

10 June 2026 at 04:03

Hi all,

I've setup an on prem Linux server, with rsyslog, that will just be used to forward syslog events from our firewall. I have it onboarded to Azure Arc and have Sentinel can receive the logs.

I'm just not clear on disk space usage. The events will be sent to Sentinel, but I'm not clear if I still have to manage the on prem disk space using something like log rotate.

Though I am looking at something like Cribl after we do our network refresh

submitted by /u/DaithiG
[link] [comments]
❌
❌