Skip to content

Latest commit

 

History

History
43 lines (34 loc) · 2.64 KB

SetupLogCollection.md

File metadata and controls

43 lines (34 loc) · 2.64 KB

Setup Log Collection

  1. Connect VMs To Log Analytics
  2. Setup Performance Counters
  3. Enable Azure Monitor for VM
  4. Enable Update Management
  5. Enable Inventory & Change Tracking
  6. Activity Log to Log Analytics Workspace
  7. Enable NSG Flow logs & Traffic Analytics

Connect VMs to Log Analytics

Setup Performance Counters

Add Linux and Windows Performance Counters configuration for Log Analytics agent to collect from VMs












Enable Azure Monitor for VM












Enable Update Management

See docs

Enable Inventory & Change Tracking

See docs












Activity Log to Log Analytics Workspace

Activity Log Categories



























NSG Flow logs & Traffic Analytics

Go to Network Watcher -> NSG Flow logs and watch out for NSG with Status "Disabled".
Select NSG with Disabled status and select

  • Flow logs = "On"
  • Flow Logs version = 2
  • select a storage account to keep the raw logs
  • Go to Traffic Analytics status switch to "On" to enable Traffic Analytics
  • select Log Analytics to store aggregated logs of Traffic Analytics