Everything You Ever Wanted to Know About Using the New Azure Monitor Agent with Microsoft Sentinel

Поділитися
Вставка
  • Опубліковано 5 вер 2024

КОМЕНТАРІ • 14

  • @AquibQureshi
    @AquibQureshi 2 роки тому +1

    thanks Team, a very good explanation about the AMA and supported scenario

  • @matthewfranklin7541
    @matthewfranklin7541 2 роки тому +1

    Many thanks, a very useful presentation!

  • @mmiltenburg
    @mmiltenburg Рік тому

    Great overview. Thanks very much!

  • @tijubrain1
    @tijubrain1 2 роки тому +1

    Awesome presentation!

  • @mmkmur1
    @mmkmur1 2 роки тому +1

    Thank you! Very informative ! One Q: When will the workbook be available ?

  • @Ruchikun
    @Ruchikun 2 роки тому

    [02:55] Contents
    [04:50] Why a new agent ?
    [09:00] Azure Monitor Agent Supportability
    [10:00] Azure arc as a requirement for non-azure machines
    [11:26] Azure arc (what is...)
    [14:15] Feature gap analysis between LAG and AMA
    [16:50] Microsoft Sentinel collection with AMA
    [19:55] Security Events before and now
    [26:16] Windows Forwarded Events
    [32:27] Data collection Rules
    [38:20] Deploying Azure Arc and AMA at scale
    [45:58] Should I migrate now?
    [48:33] Useful resources
    [48:58] Questions

  • @debarghyadasgupta1931
    @debarghyadasgupta1931 2 роки тому +1

    Loved it ❤️

  • @1213xyz
    @1213xyz 10 місяців тому

    As this webinar was recorded some time ago, I am wondering stuff mentioned in this entire video, are they still valid? Like Windows DNS/Firewall, Syslog, CEF or Sysmon not supported by AMA.
    Is this still valid?

  • @simple-security
    @simple-security 2 роки тому

    I've seen no updates on how the AMA agent will work with 'regular' windows workstations (non-servers).
    All I can find is a link to download the AMA agent (after creating a collection rule) but no details on configuring the agent for a specific workspace, etc.
    I see that workstations will need to be domain connected and synced with Azure AD.
    Will WEC be a requirement for non-domain connected workstations?

  • @rafaelruales6871
    @rafaelruales6871 2 роки тому +1

    thanks

  • @b2secops
    @b2secops 2 роки тому

    Hi, thanks for the informative video.
    Just need some clarification around the two connectors you mentioned.
    Firstly, what is the difference between the Windows Forwarded Events and Windows Security Events via AMA collectors?
    I see you used Windows forwarded events for getting events from your DC to Sentinel, can the Windows Security Events also be used to get events from your DC? or is it that it collects 'Security events' only.
    Thank you

  • @Ruchikun
    @Ruchikun 2 роки тому

    It's a shame some of these high level architectural overviews (images) are not to be found on your website. Would help to understand it

    • @MicrosoftSecurityCommunity
      @MicrosoftSecurityCommunity  2 роки тому +1

      Hi Ken, All of the presentations from the Microsoft Security Community webinars can be found at aka.ms/SecurityCommunity The link is located in the webinars and recordings section. Thank you for watching!

  • @netsocmdr
    @netsocmdr Рік тому

    :)