Start using the Azure Monitor agent instead of the Log Analytics agent before 31 August 2024

Mark Rothfield 1 Reputation point
2021-08-20T05:35:26.467+00:00

Since we use Azure Sentinel and it relies upon aggregating data into a Log Analytics workspace, what will the impact be upon Sentinel (if any) when the Log Analytics agent is retired?

Azure FastTrack
Azure FastTrack
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.FastTrack: This tag is no longer in use. Please use 'Azure Startups' instead.
75 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Alan Kinane 16,806 Reputation points MVP
    2021-08-20T09:25:04.803+00:00

    This is just the VM agent that needs to be replaced. If you are monitoring virtual machines with Azure Sentinel then you need to replace the log analytics agent with the azure monitor agent on each of the VMs. Log Analytics itself is not affected by this.

    0 comments No comments

  2. Johan Vosloo 1 Reputation point Microsoft Employee
    2021-08-22T23:55:59.603+00:00

    The Azure Monitor Agent is replacing the Log Analytics Agent for Azure Monitor, Azure Sentinel and Azure Security Center. The Azure Monitor Agent is generally available for Azure Monitor, and in private preview for Azure Sentinel and Azure Security Center at present. For more details refer to: https://video2.skills-academy.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-overview?tabs=PowerShellWindows#supported-services-and-features

    The Log Analytics Agent on VMs connected to a Log Analytics workspace used for Sentinel should be replaced with the Azure Monitor Agent before it is retired.

    0 comments No comments