Beth Pariseau · @BPariseau
318 followers · 151 posts · Server hachyderm.io
Dimitar Grozdanov · @grozdanovd
24 followers · 40 posts · Server masto.ai
Dotan Horovits #CNCFAmbassador · @horovits
181 followers · 256 posts · Server fosstodon.org

ICYMI @OpenSearchProject version 2.8 is here!
Featuring cross-cluster support for queries with PPL, experimental feature to build a chain of search processors in an cluster to integrate components such as query rewriters and results rerankers, and more:
lnkd.in/dpn3ZE2c

#opensearch #opensource #logging #loganalytics #devops

Last updated 1 year ago

otterkring · @otterkring
8 followers · 46 posts · Server social.vivaldi.net

to

Yes, it is not , but if you want to use something smaller, I created this LogAnalyticsLog module for simple posting to LogAnalytics.

github.com/OtterKring/LogAnaly

Feedback and bug reports welcome, not yet on gallery.

#powershell #logging #loganalytics #ps_framework

Last updated 1 year ago

holger · @holgerjs
31 followers · 84 posts · Server hachyderm.io

This week is all about Azure logging and monitoring. My last two days have been centered around these four pages:

**Supported metrics with Azure Monitor** (learn.microsoft.com/en-us/azur)
**Supported categories for Azure Monitor resource logs** (learn.microsoft.com/en-us/azur)
**Azure Monitor Logs table reference** (learn.microsoft.com/en-us/azur)
**Tables that support transformations in Azure Monitor Logs** (learn.microsoft.com/en-us/azur)

#azure #azuremonitor #loganalytics

Last updated 2 years ago

Daniel Neumann · @neumanndaniel
79 followers · 24 posts · Server hachyderm.io
matsest · @matsest
13 followers · 4 posts · Server hachyderm.io

TIL: How to search for two consecutive log entries in using to make an alert in using the prev() operator.

In this case the error message is generic, and I need the context of the previous message to create a specific alert.

#loganalytics #KQL #azuremonitor #mustlearnkql

Last updated 2 years ago

holger · @holgerjs
28 followers · 56 posts · Server hachyderm.io

Huh, nice, it is possible to upload custom logs to workspaces through the Client libraries.

azure.microsoft.com/en-us/upda

Details and examples on the Azure Monitor Ingestion client library for are also available: github.com/Azure/azure-sdk-for

#azure #loganalytics #azuresdk #python

Last updated 2 years ago

F0rm4t · @F0rm4t
35 followers · 37 posts · Server infosec.exchange

Tip of the day. Depending on the language of your function app different default logging is configured to send the logs via Diagnostics Settings. learn.microsoft.com/en-us/answ

#azure #loganalytics #azurefunctions #azuremonitor

Last updated 2 years ago

A lot of legacy and deprecated stuff in . Of course it is obvious that many of those will be deprecated but I think for some there was not official message.

#loganalytics #azure #azuremonitor

Last updated 2 years ago

Daniel Neumann · @neumanndaniel
79 followers · 23 posts · Server hachyderm.io
F0rm4t · @F0rm4t
27 followers · 30 posts · Server infosec.exchange
AdamFowler_IT · @AdamFowler_IT
90 followers · 18 posts · Server infosec.exchange

RT @lukasberancz: has a new . There is a new top insights panel, new activity log, tasks newly embedded into the new incident page, panel that opens within the incident page, and detailed information about entities. t.co/jfQ3JN9PhI

#microsoft #sentinel #incident #experience #loganalytics

Last updated 2 years ago

Analyst need to be able to quickly and effectively respond to security incidents. The new incident experience in Sentinel offers the analyst many new features, including top insights, an activity log, and a Log Analytics query window, to aid in triage and investigation. techcommunity.microsoft.com/t5

#securityincidents #Sentinel #loganalytics

Last updated 2 years ago

F0rm4t · @F0rm4t
22 followers · 24 posts · Server infosec.exchange

A Look at Different Options for Storing and Searching Sentinel Archived Logs.

Options available for storing and searching Sentinel logs beyond the retention period:

1. Azure Data Explorer (ADX) - recommended for users who need to frequently query the data

2. Retention and Archive Policies in Log Analytics Workspaces - recommended for users that want to query the data on occasion

3. Exporting Data to an Azure Storage Account - recommended for users who rarely need to perform queries on the data or have specific querying needs

4. Storage account export via Logic Apps - recommended for users who rarely need to perform queries on the data and have their storage account set in a different region than their log analytics workspace

Learn more here:

techcommunity.microsoft.com/t5

#azure #analytics #data #export #microsoft #MicrosoftSentinel #sentinel #siem #soar #loganalytics #logicapp #adx #azuredataexplorer #storage #storageaccount #KQL #archive #basic #log #restore #retention #cloud #multicloud #soc #compliance #hunting

Last updated 2 years ago

Daniel Neumann · @neumanndaniel
74 followers · 14 posts · Server hachyderm.io