Memory hook: An installed agent is only the start of an evidence pipeline.
Must remember
Choose the connector for the actual source and required event types. Azure Monitor Agent (AMA) uses data collection rules (DCRs) to define supported collection/routing. Associate the rule with the intended machines and verify destination tables, permissions, network access and event arrival. An agent service running locally does not prove useful records reached Sentinel.
Windows Security Events via AMA collects selected security events. Windows Event Forwarding can centralize events on collectors before ingestion; size and monitor the collector and distinguish original event source from collection host. Audit policy determines which events are generated in the first place.
Syslog via AMA collects supported Linux/appliance syslog. Common Event Format (CEF) adds a structured event representation, commonly relayed through a Linux collector. Configure the sender, transport, listener, parser and DCR consistently. Check facility/severity filters and timestamp handling; an incorrect filter can silently discard the needed evidence.
Azure Activity records control-plane operations. Resource diagnostic settings collect supported service logs/metrics, a separate surface from the subscription activity log. Azure Policy can deploy consistent diagnostic configuration at scale, but remediation and identity permissions still need validation.
Custom tables need a planned schema, timestamps and supported ingestion/transformation path. Threat-intelligence indicators require source trust, validity periods and matching logic; an indicator is not a verdict on every matching event. Check ingestion latency and duplicates, use known test records, and retain sufficient source detail to investigate normalization errors.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Windows security event selection and destination | AMA plus an associated DCR and appropriate audit policy. |
| Appliance emits CEF | Configure its supported CEF collector/connector path. |
| Collect service-specific resource logs consistently | Diagnostic settings, with Policy where suitable. |
Traps
- Azure Activity is not every resource data-plane event.
- WEF collection does not create events that audit policy never generated.
Active recall
1. What does a DCR control?
Supported data collection, transformation/routing and destination settings for associated resources.
2. Why inspect the original source field?
Forwarded events may arrive through a collector rather than directly from the affected host.
3. Syslog versus CEF?
A logging transport/message family versus a structured security event format commonly transported through syslog.
4. Why validate timestamps?
Bad time parsing can break correlation and time-window detections.
5. What should a connector smoke test prove?
A known source event arrives once with expected fields, timing and destination.