You have 200 on-premises Windows and Linux servers connected via Azure Arc. You want to ingest Windows Security Events and Syslog into a Microsoft Sentinel workspace using the Azure Monitor Agent, avoiding the legacy Log Analytics agent. What two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: In Microsoft Sentinel, enable the Windows Security Events via AMA connector and scope it to the Arc-enabled machines, allowing it to create and assign a DCR that collects the required event set., Deploy the Azure Monitor Agent extension (AzureMonitorWindowsAgent/AzureMonitorLinuxAgent) to the Arc-enabled servers so they can send data per the DCR..
Why this is the answer
To ingest Windows Security Events and Syslog from Azure Arc-enabled servers into Microsoft Sentinel using the Azure Monitor Agent (AMA), two key actions are required. First, you must enable the "Windows Security Events via AMA" connector within Microsoft Sentinel. This connector is designed to work with AMA and will automatically create and assign a Data Collection Rule (DCR) tailored to collect the necessary security events from your specified Arc-enabled machines. Second, the Azure Monitor Agent extension (AzureMonitorWindowsAgent for Windows, AzureMonitorLinuxAgent for Linux) must be deployed to all Arc-enabled servers. This agent is responsible for collecting the data according to the DCR and sending it to the Sentinel workspace. The Log Analytics agent (MMA) is a legacy solution and is not used with AMA. Windows Event Forwarding is a separate mechanism and does not replace the need for AMA and its DCRs for direct ingestion. Azure Automation accounts are for management and orchestration, not direct log forwarding to Sentinel.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed