@MarileeTurscak This is a hybrid network and the logs I want are for on-prem servers. Azure AD has diagnostic logs enabled already.
What I have figured it out is that i might need MAM sensor for the logs I Want.
Events for Servers
RT-7199
511
Reputation points
I can see logs under Advanced Hunting in the below portal for workstations. How can I see same data on-prem servers that have been onboarded and connect to LAW(Log analytics Workspace). I want IdentityLogonEvents and DeviceNetworkEvents
Microsoft 365 Security
https://security.microsoft.com
Also is there a a way to export logs to LAW, We don't Sentinel?
1 answer
Sort by: Most helpful
-
RT-7199 511 Reputation points
2021-01-29T06:57:16.923+00:00