官术网_书友最值得收藏!

Private infrastructure integrations

The primary method of integration with your private infrastructure (such as an on-premises data center) is the deployment of Syslog servers as data collectors. While endpoints can be configured to send their data to Azure Sentinel directly, you will likely want to centralize the management of this data flow. The key consideration for this deployment is the management of log data volume; if you are generating a large volume of data for security analytics, you will need to transmit that data over your internet connections (or private connections such as Express Route).

The data collectors can be configured to reduce the load by filtering the data, but a balance must be found between the volume and velocity of data collected in order to have sufficient available bandwidth to send the data to Azure Sentinel. Investment in increased bandwidth should be considered to ensure adequate capacity based on your specific needs.

A second method of integration involves investigation and automation to carry out actions required to understand and remediate any issues found. Automation may include the deployment of Azure Automation to run scripts, or through third-party solution integration, depending on the resources being managed.

Keep in mind that should your private infrastructure lose connectivity to the internet, your systems will not be able to communicate with Azure Sentinel during the outage. Investments in redundancy and fault tolerance should be considered.

主站蜘蛛池模板: 开江县| 容城县| 烟台市| 抚顺县| 郓城县| 阳山县| 孟连| 新邵县| 棋牌| 盐池县| 宁蒗| 房山区| 弥渡县| 罗江县| 深圳市| 淄博市| 阿拉善盟| 东乌珠穆沁旗| 盘山县| 剑河县| 伊通| 黎平县| 新巴尔虎左旗| 固安县| 沙雅县| 永城市| 柳河县| 砚山县| 米易县| 从化市| 明溪县| 天长市| 宁海县| 太保市| 芦溪县| 禄丰县| 武平县| 凉城县| 红安县| 贺州市| 梨树县|