Events for Servers

RT-7199 511 Reputation points
2021-01-26T20:22:14.937+00:00

I can see logs under Advanced Hunting in the below portal for workstations. How can I see same data on-prem servers that have been onboarded and connect to LAW(Log analytics Workspace). I want IdentityLogonEvents and DeviceNetworkEvents

Microsoft 365 Security
https://security.microsoft.com

Also is there a a way to export logs to LAW, We don't Sentinel?

Azure Data Explorer
Azure Data Explorer
An Azure data analytics service for real-time analysis on large volumes of data streaming from sources including applications, websites, and internet of things devices.
502 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
{count} votes

1 answer

Sort by: Most helpful
  1. RT-7199 511 Reputation points
    2021-01-29T06:57:16.923+00:00

    @MarileeTurscak This is a hybrid network and the logs I want are for on-prem servers. Azure AD has diagnostic logs enabled already.
    What I have figured it out is that i might need MAM sensor for the logs I Want.

    1 person found this answer helpful.
    0 comments No comments