Skip to content
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion cid-redirects.json
Original file line number Diff line number Diff line change
Expand Up @@ -4207,5 +4207,6 @@
"/docs/search/logreduce/detect-patterns-with-logreduce": "/docs/search/behavior-insights/logreduce/detect-patterns-with-logreduce",
"/docs/search/logreduce/influence-the-logreduce-outcome": "/docs/search/behavior-insights/logreduce/influence-the-logreduce-outcome",
"/docs/search/logreduce/understand-the-logreduce-relevance-column": "/docs/search/behavior-insights/logreduce/understand-the-logreduce-relevance-column",
"/docs/search/behavior-insights/logreduce-values": "/docs/search/behavior-insights/logreduce/logreduce-values"
"/docs/search/behavior-insights/logreduce-values": "/docs/search/behavior-insights/logreduce/logreduce-values",
"/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-cloud-to-cloud-source-migration":"/docs/send-data/collect-from-other-data-sources/azure-monitoring/azure-event-hubs-source-migration"
}
2 changes: 1 addition & 1 deletion docs/integrations/product-list/product-list-a-l.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
| <img src={useBaseUrl('img/integrations/misc/aws-simple-notification-service-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS Simple Notification Service](https://aws.amazon.com/sns/) | Automation integration: [AWS Simple Notification Service](/docs/platform-services/automation-service/app-central/integrations/aws-simple-notification-service/) |
| <img src={useBaseUrl('img/integrations/amazon-aws/waf.png')} alt="Thumbnail icon" width="50"/> | [AWS WAF](https://aws.amazon.com/waf/) | Apps: <br/>- [AWS WAF](/docs/integrations/amazon-aws/waf/)<br/>- [AWS WAF Cloud Security Monitoring and Analytics](/docs/integrations/cloud-security-monitoring-analytics/aws-waf/) <br/>Automation integration: [AWS WAF](/docs/platform-services/automation-service/app-central/integrations/aws-waf/) <br/>Cloud SIEM integration: [Amazon AWS - Web Application Firewall (WAF)](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/072b85a2-1765-45c2-911d-b0509880326e.md) |
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/axonius.png')} alt="Thumbnail icon" width="100"/> | [Axonius](https://www.axonius.com/) | Automation integration: [Axonius](/docs/platform-services/automation-service/app-central/integrations/axonius/) |
| <img src={useBaseUrl('img/integrations/misc/azure-logo.png')} alt="Thumbnail icon" width="50"/> | [Azure](https://azure.microsoft.com/en-us) | Apps: <br/>- [Azure Analysis Services](/docs/integrations/microsoft-azure/azure-analysis-services/) <br/>- [Azure API Management](/docs/integrations/microsoft-azure/azure-api-management/) <br/>- [Azure App Configuration](/docs/integrations/microsoft-azure/azure-app-configuration/) <br/>- [Azure Application Gateway](/docs/integrations/microsoft-azure/azure-application-gateway/) <br/>- [Azure App Service Environment](/docs/integrations/microsoft-azure/azure-app-service-environment/) <br/>- [Azure App Service Plan](/docs/integrations/microsoft-azure/azure-app-service-plan/) <br/>- [Azure Audit](/docs/integrations/microsoft-azure/audit/) <br/>- [Azure Automation](/docs/integrations/microsoft-azure/azure-automation/) <br/>- [Azure Backup](/docs/integrations/microsoft-azure/azure-backup/) <br/>- [Azure Batch](/docs/integrations/microsoft-azure/azure-batch/) <br/>- [Azure Cache for Redis](/docs/integrations/microsoft-azure/azure-cache-for-redis/) <br/>- [Azure Cognitive Search](/docs/integrations/microsoft-azure/azure-cognitive-search/) <br/>- [Azure Cosmos DB](/docs/integrations/microsoft-azure/azure-cosmos-db/) <br/>- [Azure Cosmos DB for PostgreSQL](/docs/integrations/microsoft-azure/azure-cosmos-db-for-postgresql/) <br/>- [Azure Data Explorer](/docs/integrations/microsoft-azure/azure-data-explorer/) <br/>- [Azure Data Factory](/docs/integrations/microsoft-azure/azure-data-factory/) <br/>- [Azure Database for MariaDB](/docs/integrations/microsoft-azure/azure-database-for-mariadb/) <br/>- [Azure Database for MySQL](/docs/integrations/microsoft-azure/azure-database-for-mysql/) <br/>- [Azure Database for PostgreSQL](/docs/integrations/microsoft-azure/azure-database-for-postgresql/) <br/>- [Azure Event Grid](/docs/integrations/microsoft-azure/azure-event-grid/) <br/>- [Azure Event Hubs](/docs/integrations/microsoft-azure/azure-event-hubs/) <br/>- [Azure Front Door](/docs/integrations/microsoft-azure/azure-front-door/) <br/>- [Azure Functions](/docs/integrations/microsoft-azure/azure-functions/) <br/>- [Azure HDInsight](/docs/integrations/microsoft-azure/azure-hdinsight/) <br/>- [Azure IoT Hub](/docs/integrations/microsoft-azure/azure-iot-hub/) <br/>- [Azure Key Vault](/docs/integrations/microsoft-azure/azure-key-vault/) <br/>- [Azure Kubernetes Service (AKS) - Control Plane](/docs/integrations/microsoft-azure/kubernetes/) <br/>- [Azure Load Balancer](/docs/integrations/microsoft-azure/azure-load-balancer/) <br/>- [Azure Logic App](/docs/integrations/microsoft-azure/azure-logic-app/) <br/>- [Azure Machine Learning](/docs/integrations/microsoft-azure/azure-machine-learning/) <br/>- [Azure Monitor Logs](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source) <br/>- [Azure Monitor Metrics](/docs/send-data/collect-from-other-data-sources/azure-monitoring/collect-metrics-azure-monitor/) <br/>- [Azure Monitoring](/docs/send-data/collect-from-other-data-sources/azure-monitoring/) <br/>- [Azure Network Interface](/docs/integrations/microsoft-azure/azure-network-interface/) <br/>- [Azure Network Watcher](/docs/integrations/microsoft-azure/network-watcher/) <br/>- [Azure Notification Hubs](/docs/integrations/microsoft-azure/azure-notification-hubs/) <br/>- [Azure Public IP Addresses](/docs/integrations/microsoft-azure/azure-public-ipAddress/) <br/>- [Azure Relay](/docs/integrations/microsoft-azure/azure-relay/) <br/>- [Azure Service Bus](/docs/integrations/microsoft-azure/azure-service-bus/) <br/>- [Azure SQL](/docs/integrations/microsoft-azure/sql/) <br/>- [Azure SQL Elastic Pool](/docs/integrations/microsoft-azure/azure-sql-elastic-pool/) <br/>- [Azure SQL Managed Instance](/docs/integrations/microsoft-azure/azure-sql-managed-instance/) <br/>- [Azure Storage](/docs/integrations/microsoft-azure/azure-storage/) <br/>- [Azure Stream Analytics](/docs/integrations/microsoft-azure/azure-stream-analytics/) <br/>- [Azure Synapse Analytics](/docs/integrations/microsoft-azure/azure-synapse-analytics/) <br/>- [Azure Virtual Network](/docs/integrations/microsoft-azure/azure-virtual-network/) <br/>- [Azure Web Apps](/docs/integrations/microsoft-azure/web-apps/) <br/>Automation integration: [Azure AD](/docs/platform-services/automation-service/app-central/integrations/azure-ad/) <br/>Collectors: <br/>- [Azure Blob Storage](/docs/send-data/collect-from-other-data-sources/azure-blob-storage/block-blob/collect-logs) <br/>- [Azure Event Hubs Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/) <br/>- [Microsoft Azure Activity Log - Cloud SIEM](/docs/cse/ingestion/ingestion-sources-for-cloud-siem/microsoft-azure-activity-log/) <br/>- [Migrating to Azure Event Hubs Cloud-to-Cloud Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-cloud-to-cloud-source-migration/) <br/>Webhook: [Webhook Connection for Microsoft Azure Functions](/docs/alerts/webhook-connections/microsoft-azure-functions/) |
| <img src={useBaseUrl('img/integrations/misc/azure-logo.png')} alt="Thumbnail icon" width="50"/> | [Azure](https://azure.microsoft.com/en-us) | Apps: <br/>- [Azure Analysis Services](/docs/integrations/microsoft-azure/azure-analysis-services/) <br/>- [Azure API Management](/docs/integrations/microsoft-azure/azure-api-management/) <br/>- [Azure App Configuration](/docs/integrations/microsoft-azure/azure-app-configuration/) <br/>- [Azure Application Gateway](/docs/integrations/microsoft-azure/azure-application-gateway/) <br/>- [Azure App Service Environment](/docs/integrations/microsoft-azure/azure-app-service-environment/) <br/>- [Azure App Service Plan](/docs/integrations/microsoft-azure/azure-app-service-plan/) <br/>- [Azure Audit](/docs/integrations/microsoft-azure/audit/) <br/>- [Azure Automation](/docs/integrations/microsoft-azure/azure-automation/) <br/>- [Azure Backup](/docs/integrations/microsoft-azure/azure-backup/) <br/>- [Azure Batch](/docs/integrations/microsoft-azure/azure-batch/) <br/>- [Azure Cache for Redis](/docs/integrations/microsoft-azure/azure-cache-for-redis/) <br/>- [Azure Cognitive Search](/docs/integrations/microsoft-azure/azure-cognitive-search/) <br/>- [Azure Cosmos DB](/docs/integrations/microsoft-azure/azure-cosmos-db/) <br/>- [Azure Cosmos DB for PostgreSQL](/docs/integrations/microsoft-azure/azure-cosmos-db-for-postgresql/) <br/>- [Azure Data Explorer](/docs/integrations/microsoft-azure/azure-data-explorer/) <br/>- [Azure Data Factory](/docs/integrations/microsoft-azure/azure-data-factory/) <br/>- [Azure Database for MariaDB](/docs/integrations/microsoft-azure/azure-database-for-mariadb/) <br/>- [Azure Database for MySQL](/docs/integrations/microsoft-azure/azure-database-for-mysql/) <br/>- [Azure Database for PostgreSQL](/docs/integrations/microsoft-azure/azure-database-for-postgresql/) <br/>- [Azure Event Grid](/docs/integrations/microsoft-azure/azure-event-grid/) <br/>- [Azure Event Hubs](/docs/integrations/microsoft-azure/azure-event-hubs/) <br/>- [Azure Front Door](/docs/integrations/microsoft-azure/azure-front-door/) <br/>- [Azure Functions](/docs/integrations/microsoft-azure/azure-functions/) <br/>- [Azure HDInsight](/docs/integrations/microsoft-azure/azure-hdinsight/) <br/>- [Azure IoT Hub](/docs/integrations/microsoft-azure/azure-iot-hub/) <br/>- [Azure Key Vault](/docs/integrations/microsoft-azure/azure-key-vault/) <br/>- [Azure Kubernetes Service (AKS) - Control Plane](/docs/integrations/microsoft-azure/kubernetes/) <br/>- [Azure Load Balancer](/docs/integrations/microsoft-azure/azure-load-balancer/) <br/>- [Azure Logic App](/docs/integrations/microsoft-azure/azure-logic-app/) <br/>- [Azure Machine Learning](/docs/integrations/microsoft-azure/azure-machine-learning/) <br/>- [Azure Monitor Logs](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source) <br/>- [Azure Monitor Metrics](/docs/send-data/collect-from-other-data-sources/azure-monitoring/collect-metrics-azure-monitor/) <br/>- [Azure Monitoring](/docs/send-data/collect-from-other-data-sources/azure-monitoring/) <br/>- [Azure Network Interface](/docs/integrations/microsoft-azure/azure-network-interface/) <br/>- [Azure Network Watcher](/docs/integrations/microsoft-azure/network-watcher/) <br/>- [Azure Notification Hubs](/docs/integrations/microsoft-azure/azure-notification-hubs/) <br/>- [Azure Public IP Addresses](/docs/integrations/microsoft-azure/azure-public-ipAddress/) <br/>- [Azure Relay](/docs/integrations/microsoft-azure/azure-relay/) <br/>- [Azure Service Bus](/docs/integrations/microsoft-azure/azure-service-bus/) <br/>- [Azure SQL](/docs/integrations/microsoft-azure/sql/) <br/>- [Azure SQL Elastic Pool](/docs/integrations/microsoft-azure/azure-sql-elastic-pool/) <br/>- [Azure SQL Managed Instance](/docs/integrations/microsoft-azure/azure-sql-managed-instance/) <br/>- [Azure Storage](/docs/integrations/microsoft-azure/azure-storage/) <br/>- [Azure Stream Analytics](/docs/integrations/microsoft-azure/azure-stream-analytics/) <br/>- [Azure Synapse Analytics](/docs/integrations/microsoft-azure/azure-synapse-analytics/) <br/>- [Azure Virtual Network](/docs/integrations/microsoft-azure/azure-virtual-network/) <br/>- [Azure Web Apps](/docs/integrations/microsoft-azure/web-apps/) <br/>Automation integration: [Azure AD](/docs/platform-services/automation-service/app-central/integrations/azure-ad/) <br/>Collectors: <br/>- [Azure Blob Storage](/docs/send-data/collect-from-other-data-sources/azure-blob-storage/block-blob/collect-logs) <br/>- [Azure Event Hubs Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/) <br/>- [Microsoft Azure Activity Log - Cloud SIEM](/docs/cse/ingestion/ingestion-sources-for-cloud-siem/microsoft-azure-activity-log/) <br/>- [Migrating to Azure Event Hubs Cloud-to-Cloud Source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/azure-event-hubs-source-migration) <br/>Webhook: [Webhook Connection for Microsoft Azure Functions](/docs/alerts/webhook-connections/microsoft-azure-functions/) |


## B
Expand Down
Original file line number Diff line number Diff line change
@@ -1,26 +1,26 @@
---
id: azure-event-hubs-cloud-to-cloud-source-migration
title: Migrating to Azure Event Hubs Cloud-to-Cloud Source
sidebar_label: Azure Event Hubs C2C Source Migration
id: azure-event-hubs-source-migration
title: Migrating from ARM based Azure Monitor Logs Collection
sidebar_label: Azure Event Hubs Source Migration
---

import useBaseUrl from '@docusaurus/useBaseUrl';

<img src={useBaseUrl('img/send-data/azure-event-hub.svg')} alt="icon" width="40"/>

As **Cloud-to-Cloud Event Hub source** supports logs, you can migrate your [ARM-based Azure Monitor Logs Collection](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source) (functions prefixed with SUMOAzureLogs). This source is available in all deployments, including FedRAMP.
As **Azure Event Hubs source** supports logs, you can migrate your [ARM-based Azure Monitor Logs Collection](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source) (functions prefixed with SUMOAzureLogs). This source is available in all deployments, including FedRAMP.

Cloud-to-Cloud sources have several advantages, including:
* Less overhead of maintenance and upgrades, since cloud-to-cloud sources are upgraded automatically for bug fixes.
* Lesser cost since the old collection method is used to create multiple resources such as storage accounts, application insights, and azure functions in your account while cloud-to-cloud sources are hosted in sumo logic infra. On the other hand, a cloud-to-cloud event hub source requires you to create only an event hub in your Azure account.
Azure Event Hubs source have several advantages, including:
* Less overhead of maintenance and upgrades, since Azure Event Hubs source are upgraded automatically for bug fixes.
* Lesser cost since the old collection method is used to create multiple resources such as storage accounts, application insights, and azure functions in your account while sources are hosted in Sumo Logic infra that requires you to create only an event hub in your Azure account.

## Step 1. Choose a migration strategy

Choose a migration strategy that is more convenient for you. Migration can be done in two ways:

### Strategy A. Existing event hub namespaces

If you want to continue using the existing **Event hubs namespaces** that are created by the ARM template, jump to the [Configuring Parameters](#step-2-configure-parameters-for-your-event-hub-cloud-to-cloud-sources) section in step 2.
If you want to continue using the existing **Event hubs namespaces** that are created by the ARM template, jump to the [Configuring Parameters](#step-2-configure-parameters-for-your-event-hub-sources) section in step 2.

The advantage of using the existing strategy is that you don’t have to recreate diagnostic settings in Azure Monitor for exporting the logs to the event hub.

Expand All @@ -30,15 +30,15 @@ You need to manually delete resources (starting with the prefix Sumo) and cannot

### Strategy B. Creating new event hub namespaces

If you want to create a new event hub namespace, see steps 1 to 3 in the [Vendor configuration](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/#vendor-configuration) section. The advantage of using this strategy is you can simply delete the resource group where the ARM template was earlier deployed. This assumes you haven’t created any additional resources in the same resource group.
If you want to create a new event hub namespace, see steps 1 to 3 in the [Vendor configuration](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/#vendor-configuration) section. The advantage of using this strategy is you can simply delete the resource group where the ARM template was earlier deployed. This assumes you haven’t created any additional resources in the same resource group.

:::note
You need to first find out what all log types are exported to your event hub and recreate the diagnostic settings for the Azure services. Thus, we recommend creating new diagnostic settings for newer namespaces so that we can delete the older ones after verifying the new collection works without any latency.
:::

After choosing one of the above two strategies, you will now have an event hub namespace that has the logs flowing to it.

## Step 2. Configure parameters for your event hub cloud-to-cloud sources
## Step 2. Configure parameters for your event hub sources

1. **Create a shared access policy**. You can create it at the namespace level if you have multiple event hubs by selecting **Shared Access Policies** on the left menu of the **Event Hubs Namespace page**.<br/> ![shared-access-policy.png](/img/send-data/shared-access-policy.png)
2. **Create a consumer group**.
Expand All @@ -55,9 +55,9 @@ Creating **Consumer Groups** is needed only for the customers using the older ev

After completing the above steps, you will have **Azure Event Hubs Namespace**, **Event Hubs Instance Name**, **Shared Access Policy**, and **Consumer Group Name** - all four parameters are required for creating an event hub source.

## Step 3. Create event hub cloud-to-cloud sources
## Step 3. Create event hub sources

For each of the event hubs present in your namespace, you need to create a cloud-to-cloud source. For more information, see [Creating Azure Event Hub Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/#vendor-configuration) section.
For each of the event hubs present in your namespace, you need to create a Azure Event Hubs source. For more information, refer to the [Creating Azure Event Hub Source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source).

:::note
We recommend giving the same source category so that your custom dashboards or apps require no changes. You can verify whether the data comes from your source using `1_source metadata`.
Expand Down Expand Up @@ -127,7 +127,7 @@ If your resource group contains only resources created by the older ARM template

## FAQ

#### After migrating to Cloud-to-Cloud, will the acquired data volume increase as compared to when configured with the previous ARM Template?
#### After migrating to Azure Event Hubs source, will the acquired data volume increase as compared to when configured with the previous ARM Template?

There won't be any change in data volume since these are the same logs we are just changing the collection method.

Expand Down
Loading
Loading