Azure Arc Isn't for workstations and the 'Legacy Agent' is going Away...

David Broggy 5,716 Reputation points MVP
2022-08-05T03:31:28.93+00:00

I have clients that must collect security event logs from some of their windows 10/11 workstations.

Currently we use the 'Legacy Window Agent' to collect these logs, but this is going away.

What options are there for collecting Windows event logs to Sentinel once this legacy agent is gone?

I believe Azure Arc/AMA only supports Windows Server versions and Linux?

Thank you.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,180 questions
Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
399 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.