I've set this up to collect Windows Event viewer logs from an Azure Windows VM... I set it to send Error and Warnings, but for some reason I only receive the warning, not the errors from the machine despite there being some... Then I set up another machine in same DCR and that receive both Errors and Warning, but the first still refuse to snd errors... Any clue what could could be wrong or how to troubleshoot?
Your videos are awesome! I hope you don't mind a little criticism. You say "OK?" every five words and that makes one a little nervous. Again, I don't mean to sound disrespectful. Anyway, these videos are just amazing, thanks for your effort !
Thanks for this video , I had some confusion about Endpoints and DCRs , Whit this video it is resolved now.
Thanks for the crisp explanation
Glad it was helpful!
you are the best
Very good overview. Thanks for your effort sharing the knowledge.
Glad it was helpful!
Very good resources, thank you very much
Glad it was helpful!
Please cover how to do this using azure policy. And if this can be done using virtualization technology such as Citrix built VMs
❤ Excellent 😃😃
Thanks 😄
Thanks for the great explanation, you're the best. I'm just wondering if I want to push the agent on 1000 VM, Is there any automated way to do that?
I've set this up to collect Windows Event viewer logs from an Azure Windows VM... I set it to send Error and Warnings, but for some reason I only receive the warning, not the errors from the machine despite there being some... Then I set up another machine in same DCR and that receive both Errors and Warning, but the first still refuse to snd errors... Any clue what could could be wrong or how to troubleshoot?
Please Videos on Microsoft Sentinel ASAP
Your videos are awesome!
I hope you don't mind a little criticism. You say "OK?" every five words and that makes one a little nervous. Again, I don't mean to sound disrespectful.
Anyway, these videos are just amazing, thanks for your effort !
Thank you so much, for the feedback 😊
Request to make a series on Sentinel.
I think this is the pre-requisite
Thanks!
Thank you :-)