Log Analytics - Windows security logs

Ashco Systems 1 Reputation point
2021-01-18T20:17:30.79+00:00

Hello

I have configured Azure Log Analytics workspace and two Windows 10 machines have Monitoring Agent installed.

The agent is successfully deployed but I cant see any Windows security event logs such as EventID 4624 and 4625.

Not sure if there is any thing else which needs to be configured, Rest of the non-security event logs are fetched in real time.

Any input or advice is much appreciated.

Thanks
Ashish

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,800 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
975 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Stanislav Zhelyazkov 21,101 Reputation points MVP
    2021-01-19T08:50:54.537+00:00

    Hi,
    Which security events are logged on your machines also depends on your local group audit policy. Make sure that these events are configured to be logged via the local group policy. If they are not logged on the servers they will not be ingested as well. Example of how these policies are configured you can see here: Configure Windows Event collection

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

  2. Andrew Blumhardt 9,491 Reputation points Microsoft Employee
    2022-06-28T21:25:56.35+00:00

    I think you can technically connect workstations to Defender for Cloud for testing but it may not be officially supported.

    Using the MMA agent, only Sentinel or MDFC have options to collect Windows Security event logs. They are in turn the result of your local audit policy. The workspace UI does not have a Security log option.

    The AMA agent can collect security event logs. You first need Aure Arc for hybrid systems.

    If you setup MDFC you need to look under the auto provisioning settings to enable security event collection. The minimal collection option will include 4625.

    0 comments No comments