Is it possible to integrate Microsoft Sentinel (Azure Sentinel) in Aria Operations for Logs
search cancel

Is it possible to integrate Microsoft Sentinel (Azure Sentinel) in Aria Operations for Logs

book

Article ID: 413784

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • It was possible to forward logs to Azure Sentinel through log forwarding configuration in the VMware Aria Operations for Logs (SaaS) UI.   VMware Aria Operations for Logs (SaaS) has being discontinued 
  • This functionality is not available in Aria Operations for Logs 

Environment

Aria Operations 8.18.x

Resolution

As there is no functionality to forward logs through Log Forwarding configuration choosing Azure Sentinel in Aria Operations for logs, the option would be to use either CFAPI or Syslog protocol as per documentation Add a VMware Aria Operations for Logs Log Forwarding Destination.  However this is dependent on whether the protocols are supported by Microsoft.  Please reach Microsoft to confirm that the Azure Sentinel supports the available protocols.