Skip to content

Commit b56f85e

Browse files
committed
Updated screenshots and removed old SIEM info
1 parent f03b03a commit b56f85e

File tree

6 files changed

+27
-68
lines changed

6 files changed

+27
-68
lines changed
12.8 KB
Loading
-117 KB
Loading
-57.7 KB
Loading
477 Bytes
Loading

articles/security-center/security-center-partner-integration.md

Lines changed: 27 additions & 68 deletions
Original file line numberDiff line numberDiff line change
@@ -11,16 +11,13 @@ ms.topic: conceptual
1111
ms.devlang: na
1212
ms.tgt_pltfrm: na
1313
ms.workload: na
14-
ms.date: 03/20/2019
14+
ms.date: 04/19/2020
1515
ms.author: memildin
1616

1717
---
1818
# Integrate security solutions in Azure Security Center
1919
This document helps you to manage security solutions already connected to Azure Security Center and add new ones.
2020

21-
> [!NOTE]
22-
> A subset of security solutions has been retired on July 31st, 2019. For more information and alternative services, see [Retirement of Security Center features (July 2019)](security-center-features-retirement-july2019.md#menu_solutions).
23-
2421
## Integrated Azure security solutions
2522
Security Center makes it easy to enable integrated security solutions in Azure. Benefits include:
2623

@@ -32,25 +29,31 @@ Currently, integrated security solutions include vulnerability assessment by [Qu
3229

3330
> [!NOTE]
3431
> Security Center does not install the Log Analytics agent on partner virtual appliances because most security vendors prohibit external agents running on their appliances.
35-
>
36-
>
32+
33+
To learn more about the integration of vulnerability scanning tools from Qualys, including a built-in scanner available to standard tier customers, see:
34+
35+
- [Integrated vulnerability scanner for virtual machines](built-in-vulnerability-assessment.md).
36+
- [Deploying a partner vulnerability scanning solution](partner-vulnerability-assessment.md).
37+
38+
Security Center also offers vulnerability analysis for your:
39+
40+
* SQL databases - see [Explore vulnerability assessment reports in the vulnerability assessment dashboard](security-center-iaas-advanced-data.md#explore-vulnerability-assessment-reports)
41+
* Azure Container Registry images - see [Azure Container Registry integration with Security Center (Preview)](azure-container-registry-integration.md)
3742

3843
## How security solutions are integrated
3944
Azure security solutions that are deployed from Security Center are automatically connected. You can also connect other security data sources, including computers running on-premises or in other clouds.
4045

41-
![Partner solutions integration](./media/security-center-partner-integration/security-center-partner-integration-fig8.png)
46+
[![Partner solutions integration](./media/security-center-partner-integration/security-center-partner-integration-fig8.png)](./media/security-center-partner-integration/security-center-partner-integration-fig8.png#lightbox)
4247

4348
## Manage integrated Azure security solutions and other data sources
4449

45-
1. Sign in to the [Azure portal](https://azure.microsoft.com/features/azure-portal/).
50+
1. From the [Azure portal](https://azure.microsoft.com/features/azure-portal/), open **Security Center**.
4651

47-
2. On the **Microsoft Azure menu**, select **Security Center**. **Security Center - Overview** opens.
48-
49-
3. Under the Security Center menu, select **Security solutions**.
52+
1. From Security Center's menu, select **Security solutions**.
5053

5154
![Security Center Overview](./media/security-center-partner-integration/overview.png)
5255

53-
In **Security solutions**, you can see the health of integrated Azure security solutions and run basic management tasks.
56+
From the **Security solutions** page, you can see the health of integrated Azure security solutions and run basic management tasks.
5457

5558
### Connected solutions
5659

@@ -60,24 +63,25 @@ The **Connected solutions** section includes security solutions that are current
6063

6164
The status of a partner solution can be:
6265

63-
* Healthy (green) - no health issues.
64-
* Unhealthy (red) - there's a health issue that requires immediate attention.
65-
* Health issues (orange) - the solution has stopped reporting its health.
66-
* Not reported (gray) - the solution hasn't reported anything yet and no health data is available. A solution's status may be unreported if it was connected recently and is still deploying.
66+
* **Healthy** (green) - no health issues.
67+
* **Unhealthy** (red) - there's a health issue that requires immediate attention.
68+
* **Stopped reporting** (orange) - the solution has stopped reporting its health.
69+
* **Not reported** (gray) - the solution hasn't reported anything yet and no health data is available. A solution's status may be unreported if it was connected recently and is still deploying.
6770

6871
> [!NOTE]
6972
> If health status data is not available, Security Center shows the date and time of the last event received to indicate whether the solution is reporting or not. If no health data is available and no alerts were received within the last 14 days, Security Center indicates that the solution is unhealthy or not reporting.
7073
>
7174
>
7275
73-
1. Select **VIEW** for additional information and options such as:
76+
Select **VIEW** for additional information and options such as:
77+
78+
- **Solution console** - Opens the management experience for this solution.
79+
- **Link VM** - Opens the Link Applications page. Here you can connect resources to the partner solution.
80+
- **Delete solution**
81+
- **Configure**
7482

75-
- **Solution console**. Opens the management experience for this solution.
76-
- **Link VM**. Opens the Link Applications page. Here you can connect resources to the partner solution.
77-
- **Delete solution**.
78-
- **Configure**.
83+
![Partner solution detail](./media/security-center-partner-integration/partner-solutions-detail.png)
7984

80-
![Partner solution detail](./media/security-center-partner-solutions/partner-solutions-detail.png)
8185

8286
### Discovered solutions
8387

@@ -86,7 +90,6 @@ Security Center automatically discovers security solutions running in Azure but
8690
> [!NOTE]
8791
> The Standard tier of Security Center is required at the subscription level for the discovered solutions feature. See [Pricing](security-center-pricing.md) to learn more about the pricing tiers.
8892
>
89-
>
9093
9194
Select **CONNECT** under a solution to integrate with Security Center and be notified of security alerts.
9295

@@ -96,55 +99,11 @@ The **Add data sources** section includes other available data sources that can
9699

97100
![Data sources](./media/security-center-partner-integration/security-center-partner-integration-fig7.png)
98101

99-
## Exporting data to a SIEM
100-
101-
> [!NOTE]
102-
> For details of a simpler method (currently in preview) for exporting data to a SIEM, see [Export security alerts and recommendations (Preview)](continuous-export.md). The new method does not use Activity Log as an intermediator and allows direct export from Security Center to Event Hubs (and then on to your SIEM), it also supports the export of Security Recommendations.
103-
104-
105-
You can configure your SIEMs or other monitoring tools to receive Azure Security Center events.
106-
107-
All events from Azure Security Center are published to Azure Monitor's Azure [Activity log](../monitoring-and-diagnostics/monitoring-overview-activity-logs.md). Azure Monitor uses [a consolidated pipeline](../azure-monitor/platform/stream-monitoring-data-event-hubs.md) to stream the data to an Event Hub where it can then be pulled into your monitoring tool.
108-
109-
The next sections describe how you can configure data to be streamed to an event hub. The steps assume that you already have Azure Security Center configured in your Azure subscription.
110-
111-
### High-level overview
112-
113-
![High-Level overview](media/security-center-export-data-to-siem/overview.png)
114-
115-
### What is the Azure security data exposed to SIEM?
116-
117-
In this version, we expose the [security alerts.](../security-center/security-center-managing-and-responding-alerts.md) In upcoming releases, we will enrich the data set with security recommendations.
118-
119-
### How to set up the pipeline
120-
121-
#### Create an Event Hub
122-
123-
Before you begin, [create an Event Hubs namespace](../event-hubs/event-hubs-create.md) - the destination for all your monitoring data.
124-
125-
#### Stream the Azure Activity Log to Event Hubs
126-
127-
See the following article [stream activity log to Event Hubs](../azure-monitor/platform/activity-logs-stream-event-hubs.md).
128-
129-
#### Install a partner SIEM connector
130-
131-
Routing your monitoring data to an Event Hub with Azure Monitor enables you to easily integrate with partner SIEM and monitoring tools.
132-
133-
See the following article for the list of [supported SIEMs](../azure-monitor/platform/stream-monitoring-data-event-hubs.md#partner-tools-with-azure-monitor-integration).
134-
135-
### Example for Querying data
136-
137-
Here are some Splunk queries you can use to pull alert data:
138-
139-
| **Description of Query** | **Query** |
140-
|----|----|
141-
| All Alerts| index=main Microsoft.Security/locations/alerts|
142-
| Summarize count of operations by their name| index=main sourcetype="amal:security" \| table operationName \| stats count by operationName|
143-
| Get Alerts info: Time, Name, State, ID, and Subscription | index=main Microsoft.Security/locations/alerts \| table \_time, properties.eventName, State, properties.operationId, am_subscriptionId |
144102

145103

146104
## Next steps
147105

148106
In this article, you learned how to integrate partner solutions in Security Center. To learn more about Security Center, see the following article:
149107

108+
* [Export security alerts and recommendations](continuous-export.md). Learn how to setup an integration with Azure Sentinel, or any other SIEM.
150109
* [Security health monitoring in Security Center](security-center-monitoring.md). Learn how to monitor the health of your Azure resources.

0 commit comments

Comments
 (0)