Window Firewall

Rohit 1 Reputation point
2020-07-23T06:19:36.093+00:00

Hello All,

Kindly suggest me how to take the Windows Firewall logs to Sentinel.

Thank You

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,767 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
990 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Cherry Zhang (Shanghai Wicresoft) 11 Reputation points
    2020-07-23T09:01:56.477+00:00

    Hi,

    Thanks for posting here.

    Please refer this official document of Connect Windows firewall:
    https://learn.microsoft.com/en-us/azure/sentinel/connect-windows-firewall

    Best regards
    Cherry


  2. VipulSparsh-MSFT 16,236 Reputation points Microsoft Employee
    2020-07-27T05:59:55.327+00:00

    @Rohit You would need to add a Data connector for windows firewall. Check the screenshot for reference :
    13852-firewall-sentinel.jpg

    Once you add above, you would need to install the agent on either on your Azure Windows Virtual machine or Non-Azure windows machine.
    When the agent are installed, you can now install the windows firewall solution for your Sentinel workspace as per following screenshot :

    13796-firewall-sentinel-solution.jpg

    -----------------------------------------------------------------------------------------------------------------

    If the suggested response helped you resolve your issue, do click on "Mark as Answer" and "Up-Vote" for the answer that helped you for benefit of the community.

    0 comments No comments