Centralizing Cloud Logs and Events with Microsoft Sentinel

Centralizing Cloud Logs and Events with Microsoft Sentinel

Source: YouTube · SANS Cloud Security · published Jun 11, 2024 · 1:07:11

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

This webcast demonstrates how to centralize cloud logs and events from AWS, Google Cloud, and Azure into a Microsoft Sentinel workspace for unified monitoring, alerting, and runbook execution 0:00.

Key Takeaways:
• The session covers a three-phase approach: intra-cloud log aggregation within each cloud provider, cross-cloud data transfer patterns, and finally connecting everything into Sentinel data connectors 0:52
• Intra-cloud log aggregation is essential because enterprise cloud environments have multiple accounts, subscriptions, or projects all emitting log events that must be consolidated into a single location rather than scattered across individual accounts 4:04
• For Azure centralized logging, a dedicated monitoring subscription should contain an audit log storage account configured with an immutable lock policy to enforce retention periods (typically 1-7 years depending on industry requirements) 4:57
• Lifecycle policies can be applied to transition logs from warm storage to cold storage for cost savings, though cold storage is not ideal for active querying and serves more as a backup 5:41
• A Log Analytics Workspace is the recommended approach in Azure for actively querying centralized log data 6:05

This webcast provides practical guidance for security teams looking to achieve cross-cloud visibility through Microsoft Sentinel, drawing from the SANS SEC 549 curriculum.

Sources:

  • 0:00 Introduction to centralizing cloud logs with Microsoft Sentinel
  • 0:52 Agenda overview: intra-cloud aggregation, data transfer, and Sentinel connect

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hey everybody, welcome to today's webcast, centralizing cloud logs and events with Microsoft Sentinel. Today, uh, myself, Eric Johnson, and my co-presenter, David Hazar, are going to be walking you through the journey of a log file from AWS and from Google and inside of the Azure cloud as well into the Microsoft Sentinel workspace that we've got set up for a demo environment to show you how all of these different little connectors can be glued together to give you a central area to review your events, set up alerts, runbooks, and all the fun things that we know and love about Sentinel. With that, let's do some quick introductions here. After we do some introductions, uh I'll walk you through the intra cloud logging aggregation. So, that's really going to be focused on AWS and Google gettin…