Last updated
Was this helpful?
Last updated
Was this helpful?
Panther supports ingesting by .
It's also possible to ingest logs using this source by including the during , below.
Panther retrieves Azure Monitor files once per hour.
You'll first create an Azure Blob Storage source in Panther, then configure Azure to export logs to that location.
In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.
In the upper right corner, click Create New.
Search for "Azure Monitor," then click its tile.
Click Start Setup.
Follow Panther's instructions for configuring an .
During , if you choose to create your Azure resources manually (instead of using Terraform), skip , as one will automatically be created in your storage account in Step 2, below.
After you have completed these instructions, continue to , below.
To export Azure Monitor logs to a Blob storage container:
In your Azure dashboard, navigate to the Monitor service.
In the left-hand navigation panel, click Activity Log.
Near the top of the page, click Export Activity Logs.
Click Add Diagnostic Setting.
On the Diagnostic setting page, provide values for the following fields:
Diagnostic setting name: Enter a descriptive name.
Categories (under Logs): Select each of the log categories you are interested in ingesting:
Destination details: Select the Archive to a storage account checkbox, then select your destination Storage account.
In the upper left corner, click Save.
Monitor Activity logs will now be saved to a Blob container in your storage account.
Click on your newly created container with the name insights-activity-logs
, then in the left-hand navigation bar, click Access Control (IAM).
Click Add Role Assignment.
Click on the Members tab.
Click +Select Members.
Click Review+Assign.
Remember that because Panther retrieves Azure Monitor files once per hour, there could be a delay of up to one hour before initial data arrives in Panther.
Panther supports Azure Monitor Activity logs which are handled by the Azure.MonitorActivity schema.
(Microsoft Defender for Cloud)
Click +Add.
Search for "Storage Blob Data Reader" and select the matching role that populates.
Search for the name of the registered app you created during the , and click Select.
Connecting Azure Monitor logs to your Panther Console