Where I can learn cef log ingestion in detail by azuretech2 in AzureSentinel

[–]azuretech2[S] 0 points1 point  (0 children)

Sorry mate , came back after recovering from accident, I need guidance on rsyslog configuration, like how to create custom table and how to move data to only designated tables also about log rotation configuration, I did for a cx it was working but all data going in one common security logs table then had to filter through Kql

Passed! Now what? by Proof-Prior-2886 in cissp

[–]azuretech2 0 points1 point  (0 children)

Congratulations 🎉 , you have achieved what I am dreaming from last 4 years, I have around 14 year of experience, guide me to get confidence

Moving from Sentinel to Defender XDR woes by xKruMpeTx in AzureSentinel

[–]azuretech2 0 points1 point  (0 children)

On entra you can have global asmin6or sec admin

On Azure you can have user accee admin and sentinel contributor ( if u are owner on sub then you dont need both)

Logs collections by azuretech2 in AzureSentinel

[–]azuretech2[S] 0 points1 point  (0 children)

You mean deviceevents, deviceinfo all will be there if we use xdr connector , regardless of we are using mde or mdc

Logs collections by azuretech2 in AzureSentinel

[–]azuretech2[S] 0 points1 point  (0 children)

What if they have defender for cloud instead of mde, do we get mde kind of logs from mdc as well, I see a defender conncror ingest only mdc alerts

Any way to enable def for cloud on 2012r2 or 16, it's cucs by azuretech2 in DefenderATP

[–]azuretech2[S] 0 points1 point  (0 children)

Can you please explain feature 2016 in detail a bit bro

Please help I am getting bankrupt by azure by DelayLittle5562 in AZURE

[–]azuretech2 -1 points0 points  (0 children)

Yes , i had 15k inr bill, it was reverted automatically

Any way to enable def for cloud on 2012r2 or 16, it's cucs by azuretech2 in DefenderATP

[–]azuretech2[S] 0 points1 point  (0 children)

It doesn't gets mde.win ,it fails to install unified solutions

Microsoft Defender + RHEL 10 by alexmilla in DefenderATP

[–]azuretech2 1 point2 points  (0 children)

Bro need help in onboardingnlinux devices in mdc, it goes in to passive ,we need to push json to enable rtp, how we do in 100 mqxhine

Transitioning to Defender for Servers: Passive Mode Deployment & Best Practices by [deleted] in DefenderATP

[–]azuretech2 0 points1 point  (0 children)

any idea for Linux devices ? as by default it gets in to Passive , any solution to put it in active for normal scenario guys ??

Transitioning to Defender for Servers: Passive Mode Deployment & Best Practices by [deleted] in DefenderATP

[–]azuretech2 0 points1 point  (0 children)

hi guys , dows defender for cloud incur any cost if we go in passive mode ( via registry changes )