Forward Azure logs to non-Azure SIEM (Amazon Elasticsearch)

Gino Huang 1 Reputation point
2021-03-08T04:56:13.207+00:00

Hi,

I want centralized logs to Amazon Elasticsearch, how to forward Azure logs to there? It seems not list in the partner tools with Azure Monitor integration.

Did Azure can actively send records or query from AWS?

I already have Azure Monitor.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,971 questions
Azure Event Hubs
Azure Event Hubs
An Azure real-time data ingestion service.
591 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. PRADEEPCHEEKATLA-MSFT 84,456 Reputation points Microsoft Employee
    2021-03-09T12:15:05.503+00:00

    Hello @Gino Huang ,

    Welcome to the Microsoft Q&A platform.

    Unfortunately, you cannot forward Azure Logs to non-Azure SIEM.

    Using Azure Monitor to route monitoring data to an Azure Event Hub allows you to easily integrate with some external SIEM and monitoring tools. The following partners are known to have integration via Event Hub.

    75825-image.png.

    I would suggest you to provide feedback on the same:

    https://feedback.azure.com/forums/911458-event-hubs

    All of the feedback you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Azure.

    Hope this helps. Do let us know if you any further queries.

    ------------

    Please don’t forget to Accept Answer and Up-Vote wherever the information provided helps you, this can be beneficial to other community members.


  2. Gino Huang 1 Reputation point
    2021-03-29T02:03:39.43+00:00

    Hello @PRADEEPCHEEKATLA-MSFT

    Thanks, I will try to see if it is available.

    0 comments No comments