- Learn Azure Sentinel
- Richard Diver Gary Bushey Jason S. Rader
- 232字
- 2021-06-30 15:08:16
Private infrastructure integrations
The primary method of integration with your private infrastructure (such as an on-premises data center) is the deployment of Syslog servers as data collectors. While endpoints can be configured to send their data to Azure Sentinel directly, you will likely want to centralize the management of this data flow. The key consideration for this deployment is the management of log data volume; if you are generating a large volume of data for security analytics, you will need to transmit that data over your internet connections (or private connections such as Express Route).
The data collectors can be configured to reduce the load by filtering the data, but a balance must be found between the volume and velocity of data collected in order to have sufficient available bandwidth to send the data to Azure Sentinel. Investment in increased bandwidth should be considered to ensure adequate capacity based on your specific needs.
A second method of integration involves investigation and automation to carry out actions required to understand and remediate any issues found. Automation may include the deployment of Azure Automation to run scripts, or through third-party solution integration, depending on the resources being managed.
Keep in mind that should your private infrastructure lose connectivity to the internet, your systems will not be able to communicate with Azure Sentinel during the outage. Investments in redundancy and fault tolerance should be considered.
- RESTful Java Web Services Security
- 工業互聯網安全防護與展望
- 諸神之眼:Nmap網絡安全審計技術揭秘
- 網絡運維親歷記 (網絡運維紀實文學)
- Testing and Securing Android Studio Applications
- Digital Forensics with Kali Linux
- 數據安全領域指南
- CTF那些事兒
- Learning Pentesting for Android Devices
- Cybersecurity Threats,Malware Trends,and Strategies
- 網絡空間安全實戰基礎
- ATT&CK與威脅獵殺實戰
- 5G網絡安全規劃與實踐
- CPK通向賽博安全之路:理論與實踐CPK Solution to Cyber Security:Theory and Practice
- CTF網絡安全競賽入門教程