How to prepare to collect security log data from your Azure Windows virtual machines. You require two things:
- Log Analystics Workspace to be created
- The agent to be installed on the Virtual machine.
This guide shows how to setup the workspace and install the agents on the virtual machine.
Create a Log Analytics Workspace
Pricing is Pay as you go
Next you connect to the data source
Click Virtual Machines > Select Virtual Machine and click Connect.
The Agent is then automatically installed and ready to configure for the log analytics workspace
Next Configure workspace under advanced settings. See MS Doc Quick Start Guide
Windows event log collect from Windows VM
- Click Data > Windows Event Logs.
- Add an event log. Example type System and then select “+”.
- In the table, check the options Error and Warning.
- Select Save at the top of the page to save the configuration.
Example of what you can see in an Azure Activity Log
- Event Initiated by
The following is a list of key executables and a description of there task or roles when working with Trend Micro OfficeScan 11 XG. This is not a complete list.
||Task or Role
||UNC based agent deployment program
||OfficeScan agent plugin manager
||Interface to OfficeScan DB
||Smart Scan functionality, File reputation and Web reputation
||Scanning, collects logs & requests for malware info
||Central Management for OfficeScan
||Interface to Active Directory
||Migrating OfficeScan HTTP DB to SQL
||GetInfo, Uninstall, Install OfficeScan server
||Adjust setting, such as increase time to download for Updated Agents
||Prevent unauthorised change to the registry
||Server – Agent comms
||Sending and recieveing HTTP/HTTPS traffic
||Vulnerabity scanner with option to deploy agent
The following is a list of key logs and a description of there task or roles when working with Trend Micro OfficeScan 11 XG. This is not a complete list.
||Client / Agent port info / Install info
||OfficeScan server install info
||OfficeScan debugging log
Please note, this info may be incorrect. These are study notes and not official material. Comments are my own.
This site is funded by advert clicks. If you found this post useful, please click on an ad of interest.