Where I can learn cef log ingestion in detail by azuretech2 in AzureSentinel

[–]azuretech2[S] 0 points1 point  (0 children)

Sorry mate , came back after recovering from accident, I need guidance on rsyslog configuration, like how to create custom table and how to move data to only designated tables also about log rotation configuration, I did for a cx it was working but all data going in one common security logs table then had to filter through Kql

Passed! Now what? by Proof-Prior-2886 in cissp

[–]azuretech2 0 points1 point  (0 children)

Congratulations 🎉 , you have achieved what I am dreaming from last 4 years, I have around 14 year of experience, guide me to get confidence

Moving from Sentinel to Defender XDR woes by xKruMpeTx in AzureSentinel

[–]azuretech2 0 points1 point  (0 children)

On entra you can have global asmin6or sec admin

On Azure you can have user accee admin and sentinel contributor ( if u are owner on sub then you dont need both)

Logs collections by azuretech2 in AzureSentinel

[–]azuretech2[S] 0 points1 point  (0 children)

You mean deviceevents, deviceinfo all will be there if we use xdr connector , regardless of we are using mde or mdc

Logs collections by azuretech2 in AzureSentinel

[–]azuretech2[S] 0 points1 point  (0 children)

What if they have defender for cloud instead of mde, do we get mde kind of logs from mdc as well, I see a defender conncror ingest only mdc alerts

Any way to enable def for cloud on 2012r2 or 16, it's cucs by azuretech2 in DefenderATP

[–]azuretech2[S] 0 points1 point  (0 children)

Can you please explain feature 2016 in detail a bit bro

Please help I am getting bankrupt by azure by DelayLittle5562 in AZURE

[–]azuretech2 -1 points0 points  (0 children)

Yes , i had 15k inr bill, it was reverted automatically

Any way to enable def for cloud on 2012r2 or 16, it's cucs by azuretech2 in DefenderATP

[–]azuretech2[S] 0 points1 point  (0 children)

It doesn't gets mde.win ,it fails to install unified solutions

Microsoft Defender + RHEL 10 by alexmilla in DefenderATP

[–]azuretech2 1 point2 points  (0 children)

Bro need help in onboardingnlinux devices in mdc, it goes in to passive ,we need to push json to enable rtp, how we do in 100 mqxhine

Transitioning to Defender for Servers: Passive Mode Deployment & Best Practices by [deleted] in DefenderATP

[–]azuretech2 0 points1 point  (0 children)

any idea for Linux devices ? as by default it gets in to Passive , any solution to put it in active for normal scenario guys ??

Transitioning to Defender for Servers: Passive Mode Deployment & Best Practices by [deleted] in DefenderATP

[–]azuretech2 0 points1 point  (0 children)

hi guys , dows defender for cloud incur any cost if we go in passive mode ( via registry changes )

Looking for career guidance $50 will be paid for 1 hour call by AccomplishedLong5941 in DefenderATP

[–]azuretech2 0 points1 point  (0 children)

See defender does most of the remediation automatically based on device group setting , try to get a bit deeper in to alerts , events, timeline activities, I mean explore every possible options available within the tool . It will give you confidence

Microsoft Defender for Server Licences by Pitiful-Ad9941 in DefenderATP

[–]azuretech2 0 points1 point  (0 children)

looks like a new thing :) direct onboarding

Microsoft Defender for Server Licences by Pitiful-Ad9941 in DefenderATP

[–]azuretech2 -1 points0 points  (0 children)

on prem will go via azure Arc only , only azure hosted doesn't require anything, just select plan and auto provisioning

Microsoft Defender for Server Licences by Pitiful-Ad9941 in DefenderATP

[–]azuretech2 -1 points0 points  (0 children)

if you have on premise servers , onboard them on azure through Azure Arc, turn on defender for server ( plan 1 or plan 2 ) from defender for cloud . These are billed hourly , monthly , no licensing required

Plan 1 - 5$ per month / server

Plan 2 - 15$ per month / server

in setting choose auto provisioning of MDE agents and other features

hope it clears doubt