we have created two Web Gateway servers in Azure for our customer to provide an ICAP Service. So far testing has gone well.
What are investigating now is the ability to send syslog events to log analytics. I believe to do this we need to load the Log Analytics agent on the linux VM's. Would it be possible for us to load this agent on the Web Gateway Servers?
If not is there an alternative way to send the syslog data to log analytics?
Or is there an alternative way to get events out of the Web Gateway servers to log analytics?
We are simply trying to get notified when there is malware detected.
Or do we have to send the syslog events to the on premise SIEM ?
If so it just seems a bit silly to be dependent on this on-premise connection for a service the customer wanted to host in Azure.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.