Windows VM Server as Log Analytics Gateway to Azure Sentinel

Andrew Craig 21 Reputation points
2021-02-18T17:18:52.327+00:00

We are planning an Azure Sentinel deployment and want all of our data sources to first log to an on-prem gateway server, and then send off to Sentinel. Microsoft documentation keeps mentioning a Linux server to be used for this log forwarder but can a Windows server be used instead?

Would this just require a Windows server with the Log Analytics agent (Microsoft Monitoring Agent) installed to collect the logs? I see system requirements for the Linux forwarder, but what are the requirements for Windows?

Thank you,
Andrew

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
990 questions
{count} votes

Accepted answer
  1. CyrAz 5,181 Reputation points
    2021-02-23T14:41:34.35+00:00

    If I'm not mistaken :

    • Log Analytics Gateway is really not much more than a simplified HTTP proxy, for environments where the Log Analytics agents don't have direct access to the internet.
    • Syslog messages can only be forwarded through a linux log analytics agent (which in turn may need to connect through a log analytics gateway to reach Azure). The windows agent can't act as a syslog receiver.
    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,461 Reputation points Microsoft Employee
    2021-03-02T19:04:07.773+00:00

    @Andrew Craig
    Thank you for the quick follow up on this and I'm glad that you'll be working with a partner to help you resolve this issue! I was also able to get a response from our support team this morning and will post their update below.

    Update:
    This has to be a Linux box. Windows servers are not able to send Syslog/CEF data.

    Thank you again for your time and patience throughout this issue.

    0 comments No comments