Home NewsX What to do if your Sentinel Data Connector shows as [DEPRECATED]

What to do if your Sentinel Data Connector shows as [DEPRECATED]

by info.odysseyx@gmail.com
0 comment 21 views


Several Sentinel users have raised concerns that several data connectors they were using are suddenly showing as deprecated in the user interface.

ddep.jpg

The first thing to know is that the data flow is uninterrupted. It’s still happily passing through to the CommonSecurityLog or Syslog tables. Analysis rules still apply to the data. Workbooks and playbooks should always work the same way.

This change was intended to provide real benefits. We recently deprecated the log analysis agent, also known as MMA or OMS agent, and replaced it with the new Azure Monitor agent (AMA). There are many benefits to switching to an AMA agent, including faster performance and multihoming support. Learn more It’s here.

However, for our purposes, the advantage is that we can use a single connector (the Common Event Format for AMA) for everything we want to log to the CommonSecurityLog, rather than requiring many different connectors based on a specific solution. There is another one called Syslog for AMA that does the same thing for Syslog. You can find documentation on how to install CEF and Syslog data connectors. here.

I have one more question for you. If you’ve already switched to Common Event Format data connectors and want to clean up by deleting deprecated connectors, you can’t do that. An error occurs. We are working on resolving the issue.





Source link

You may also like

Leave a Comment

Our Company

Welcome to OdysseyX, your one-stop destination for the latest news and opportunities across various domains.

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

Laest News

@2024 – All Right Reserved. Designed and Developed by OdysseyX