Security Center and Sentinel shared LAW

Justin Von Weicahrdt 1 Reputation point
2021-05-04T01:20:50.787+00:00

We are working on a project deploying Azure Security Centre and Azure Defender (leveraging Qualys scanning engine) for vulnerability scanning capability, and consolidate the logs and metrics to a centralised Log Analytics Workspace. We also have a Sentinel project using its Log Analytics Workspace. Am i correct in saying that when we deploy the LAW agents and Qualys agent it should be pointing to the same central log analytics that Sentinel uses? Or should it be using another Log Analytics Workspace and then use the connector to Sentinel? The Sentinel Project is looking for clarification why we should be using the Sentinel LAW instead of our own.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,204 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
991 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Yash Mudaliar 191 Reputation points Microsoft Employee
    2021-05-04T08:15:11.88+00:00

    Hi @Justin Von Weicahrdt ,

    Azure Security Center mainly uses LAW when you need to export alerts, recommendations or logs to Sentinel. It is done by enabling 'Continuous Export' from Security Center. (Can share the steps on how to do that if you need).
    I think it's a good reason to point out that using the Sentinel LAW gives a better and easier integration between Security Center and Sentinel.

    If my answer was helpful, please upvote and if I resolved your question please 'Accept it as an answer'.

    3 people found this answer helpful.