You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/working-with-log-analytics-agent.md
+10-5Lines changed: 10 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ author: dcurwin
5
5
ms.author: dacurwin
6
6
ms.topic: how-to
7
7
ms.custom: ignite-2022
8
-
ms.date: 09/12/2022
8
+
ms.date: 07/31/2023
9
9
---
10
10
11
11
# Collect data from your workloads with the Log Analytics agent
@@ -115,7 +115,7 @@ You can define the level of security event data to store at the workspace level.
115
115
1. From Defender for Cloud's menu in the Azure portal, select **Environment settings**.
116
116
1. Select the relevant workspace. The only data collection events for a workspace are the Windows security events described on this page.
117
117
118
-
:::image type="content" source="media/enable-data-collection/event-collection-workspace.png" alt-text="Screenshot of setting the security event data to store in a workspace.":::
118
+
:::image type="content" source="media/enable-data-collection/event-collection-workspace.png" alt-text="Screenshot of setting the security event data to store in a workspace." lightbox="media/enable-data-collection/event-collection-workspace.png":::
119
119
120
120
1. Select the amount of raw event data to store and select **Save**.
121
121
@@ -125,17 +125,22 @@ You can define the level of security event data to store at the workspace level.
125
125
126
126
To manually install the Log Analytics agent:
127
127
128
-
1. Turn off the Log Analytics agent in **Environment Settings** > Monitoring coverage > **Settings**.
128
+
1. In the Azure portal, navigate to the Defender for Cloud's **Environment Settings** page.
129
+
1. Select the relevant subscription and then select **Settings & monitoring**.
:::image type="content" source="media/working-with-log-analytics-agent/manual-provision.png" alt-text="Screenshot of turning off the Log Analytics setting." lightbox="media/working-with-log-analytics-agent/manual-provision.png":::
131
133
134
+
1. Optionally, create a workspace.
132
135
1. Enable Microsoft Defender for Cloud on the workspace on which you're installing the Log Analytics agent:
133
136
134
137
1. From Defender for Cloud's menu, open **Environment settings**.
135
138
136
139
1. Set the workspace on which you're installing the agent. Make sure the workspace is in the same subscription you use in Defender for Cloud and that you have read/write permissions for the workspace.
137
140
138
-
1. Select **Microsoft Defender for Cloud on**, and **Save**.
141
+
1. Select one or both "Servers" or "SQL servers on machines"(Foundational CSPM is the free default), and then select **Save**.
142
+
143
+
:::image type="content" source="media/working-with-log-analytics-agent/apply-plan-to-workspace.png" alt-text="Screenshot that shows where to set the workspace on which you're installing the agent." lightbox="media/working-with-log-analytics-agent/apply-plan-to-workspace.png":::
139
144
140
145
>[!NOTE]
141
146
>If the workspace already has a **Security** or **SecurityCenterFree** solution enabled, the pricing will be set automatically.
0 commit comments