Azure Log Analytics Workspace Design

Поділитися
Вставка
  • Опубліковано 18 жов 2024

КОМЕНТАРІ • 4

  • @liudmylasoderstrom6226
    @liudmylasoderstrom6226 2 місяці тому

    That’s a great new video, Patrik!
    Thank you for your work!!

  • @NicolasLhoir
    @NicolasLhoir 2 місяці тому +1

    Tks Patrick, what options do we have when spliting Security law from application law: do applications havé to send twice the log ?

    • @PatriksTechLightning
      @PatriksTechLightning  2 місяці тому +1

      Depends 😎 If you indeed need to have seperate LAW's , one for security and one for Application it may result in sending the logs twice. I would try to avoid those scenarios as much as possible.
      You can fine tune VM's with DCR's and specify which exact logs to send to what LAW. Technically, it's possible to split it up.
      It all comes down to governance. If you send all the logs (security + application) to a single LAW, is table based RBAC an option ? Meaning, only certain administrators have access to the security logs and other the application. Do you have a security policy in place which prohibits this ?
      Bottom line: try to see if a single workspace can handle it.