Additional logs for Azure VM filebeat module in my operating system

Carolina Zamisnicu 316 Reputation points
2021-06-15T10:40:46.857+00:00

Hello,

I have a question regarding the logs received from Azure. Is there any possibility that I might receive other logs that can be useful for an analyst besides the internal logs that I'm receiving from my VM (the linux kind of logs that I'm receiving due to the Azure filebeat module that I installed on my VM)?
For example, if Windows is creating other logs for my VM while the internal ingestion of data is being made in the VM environment.

If there are any other logs, besides that ones that I ingest in Elastic from my VM, how can I collect them? Should I use a separate storage account for them?

I wonder that if there are other logs they might be interesting for me (from an analyst perspective) and I should also take them into consideration.
Thank you!

Windows API - Win32
Windows API - Win32
A core set of Windows application programming interfaces (APIs) for desktop and server applications. Previously known as Win32 API.
2,428 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,639 questions
{count} votes