Security needs Windows Security events and syslog from lock-lab virtual machines in a Log Analytics workspace. What should the Azure security engineer create for Azure Monitor Agent?
Select an answer to reveal the explanation.
Short Explanation
Forget the old MMA nostalgia tour. Stand up an Azure Monitor data collection rule for Azure Monitor Agent, point it at those Security events and syslog, and associate it so the workspace actually gets the goods.
Full Explanation
Azure Monitor data collection rules (DCRs) define what Azure Monitor Agent collects—such as Windows Security events and syslog—and where that data is sent. The retired Log Analytics / MMA agent is not the first-choice answer for current designs. Network Watcher NSG flow logs and Defender for Cloud Apps address different monitoring needs than host security-event collection via DCR.