Skip to content
Open
2 changes: 1 addition & 1 deletion blog-service/2022/12-31.md
Original file line number Diff line number Diff line change
Expand Up @@ -618,7 +618,7 @@ New - We are delighted to announce the release of the [Sumo Logic Amazon Route 5

Update - The [AWS Kinesis Firehose for Logs Source](/docs/send-data/hosted-collectors/amazon-aws/aws-kinesis-firehose-logs-source) now has the option to collect undelivered logs from the backup directory.

Update - The [Azure Event Hubs Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source) now supports Processing Rules and timestamp configuration options for logs.
Update - The [Azure Event Hubs Source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/) now supports Processing Rules and timestamp configuration options for logs.

---
## March 17, 2022 (Apps)
Expand Down
6 changes: 3 additions & 3 deletions cid-redirects.json
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,7 @@
"/03Send-Data/Collect-from-Other-Data-Sources/Azure_Monitoring/Collect_Metrics_from_Azure_Monitor": "/docs/send-data/collect-from-other-data-sources/azure-monitoring/collect-metrics-azure-monitor",
"/03Send-Data/Collect-from-Other-Data-Sources/Azure-API-Management-Collector": "/docs/send-data/collect-from-other-data-sources/azure-monitoring",
"/03Send-Data/Collect-from-Other-Data-Sources/Azure-API-Management": "/docs/send-data/collect-from-other-data-sources/azure-monitoring",
"/03Send-Data/Collect-from-Other-Data-Sources/Azure-Event-Hubs-Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source",
"/03Send-Data/Collect-from-Other-Data-Sources/Azure-Event-Hubs-Source": "/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source",
"/03Send-Data/Collect-from-Other-Data-Sources/Collect_AWS_Lambda_Logs_using_an_Extension": "/docs/send-data/collect-from-other-data-sources/collect-aws-lambda-logs-extension",
"/03Send-Data/Collect-from-Other-Data-Sources/Collect_AWS_Lambda_Logs_using_an_Extension/Performance_Impact_and_Failover_Handling": "/docs/send-data/collect-from-other-data-sources/performance-impact-failover-handling",
"/03Send-Data/Collect-from-Other-Data-Sources/Collect-from-Docker-Containers/01-Configure-a-Docker-Collector": "/docs/send-data/collect-from-other-data-sources/docker-collection-methods",
Expand Down Expand Up @@ -295,7 +295,7 @@
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/AWS_Cost_Explorer_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-cost-explorer-source",
"/docs/send-data/hosted-collectors/amazon-aws/aws-cost-explorer": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-cost-explorer-source",
"/docs/send-data/hosted-collectors/amazon-aws/aws-cost-explorer-source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-cost-explorer-source",
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Azure_Event_Hubs_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source",
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Azure_Event_Hubs_Source": "/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source",
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Carbon_Black_Cloud_Source": "/docs/cse/ingestion/ingestion-sources-for-cloud-siem/carbon-black",
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Carbon_Black_Inventory_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/carbon-black-inventory-source",
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Cisco_AMP_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cisco-amp-source",
Expand Down Expand Up @@ -2138,7 +2138,6 @@
"/cid/24000": "/docs/send-data/installed-collectors/sources/preconfigure-machine-collect-remote-windows-events",
"/cid/24841": "/docs/integrations/security-threat-detection/palo-alto-networks-9",
"/cid/25611": "/docs/integrations/saas-cloud/akamai-cloud-monitor",
"/cid/25612": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source",
"/cid/25613": "/docs/cse/ingestion/ingestion-sources-for-cloud-siem/carbon-black",
"/cid/25614": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/carbon-black-inventory-source",
"/cid/25615": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cisco-amp-source",
Expand Down Expand Up @@ -3009,6 +3008,7 @@
"/cid/1150": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/slack-source/",
"/cid/1151": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/box-source/",
"/cid/1152": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/dropbox-source/",
"/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source": "/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/",
"/Cloud_SIEM_Enterprise": "/docs/cse",
"/Cloud_SIEM_Enterprise/Administration": "/docs/cse/administration",
"/Cloud_SIEM_Enterprise/Administration/Cloud_SIEM_Enterprise_Feature_Update_(2022)": "/docs/cse/administration",
Expand Down
2 changes: 1 addition & 1 deletion docs/integrations/app-development/github.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ The Sumo Logic App for GitHub connects to your GitHub repository at the Organiza
:::note
If you want to collect audit logs for [GitHub Enterprise](https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise):

1. Follow the instructions on [how to stream GitHub Enterprise Audit Logs to an Amazon S3 bucket](https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-amazon-s3) or [Azure Event Hubs](https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-azure-event-hubs). Use an [Amazon S3 source](/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source) or [Event Hubs Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source) to send those logs to Sumo Logic.
1. Follow the instructions on [how to stream GitHub Enterprise Audit Logs to an Amazon S3 bucket](https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-amazon-s3) or [Azure Event Hubs](https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-azure-event-hubs). Use an [Amazon S3 source](/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source) or [Event Hubs Source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/) to send those logs to Sumo Logic.
1. This app will work with [global webhook for Github enterprise](https://docs.github.com/en/enterprise-cloud@latest/webhooks/using-webhooks/creating-webhooks#creating-a-global-webhook-for-a-github-enterprise), [organization webhook](https://docs.github.com/en/enterprise-cloud@latest/webhooks/using-webhooks/creating-webhooks#creating-an-organization-webhook) or [repository webhook](https://docs.github.com/en/enterprise-cloud@latest/webhooks/using-webhooks/creating-webhooks#creating-a-repository-webhook).

Make sure not to select the same webhook event type at multiple levels (i.e., enterprise, organization, or repository) to avoid ingesting duplicate data.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ For Azure App Service Plan, you can collect the following metrics:

Azure service sends monitoring data to Azure Monitor, which can then [stream data to Eventhub](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/stream-monitoring-data-event-hubs). Sumo Logic supports:

* Logs collection from [Azure Monitor](https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-get-started) using our [Azure Event Hubs source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/).
* Logs collection from [Azure Monitor](https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-get-started) using our [Azure Event Hubs source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/).
* Metrics collection using our [Azure Metrics Source](/docs/send-data/hosted-collectors/microsoft-source/azure-metrics-source).

You must explicitly enable diagnostic settings for each Azure App Service plan you want to monitor. You can forward logs to the same event hub provided they satisfy the limitations and permissions as described [here](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/diagnostic-settings?tabs=portal#destination-limitations).
Expand Down
2 changes: 1 addition & 1 deletion docs/integrations/microsoft-azure/azure-event-hubs.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ For more information on supported metrics, refer to [Azure documentation](https:

Azure service sends monitoring data to Azure Monitor, which can then [stream data to Eventhub](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/stream-monitoring-data-event-hubs). Sumo Logic supports:

* Logs collection from [Azure Monitor](https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-get-started) using our [Azure Event Hubs source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/).
* Logs collection from [Azure Monitor](https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-get-started) using our [Azure Event Hubs Source for Logs](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/).
* Metrics collection using our [Azure Metrics Source](/docs/send-data/hosted-collectors/microsoft-source/azure-metrics-source).

You must explicitly enable diagnostic settings for each Event Hub Namespace you want to monitor. You can forward logs to the same event hub provided they satisfy the limitations and permissions as described [here](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/diagnostic-settings?tabs=portal#destination-limitations).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ API events and workflow events have a common structure, but with a few differenc

Azure service sends monitoring data to Azure Monitor, which can then [stream data to Eventhub](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/stream-monitoring-data-event-hubs). Sumo Logic supports:

* Logs collection from [Azure Monitor](https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-get-started) using our [Azure Event Hubs source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/).
* Logs collection from [Azure Monitor](https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-get-started) using our [Azure Event Hubs source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/).

When you configure the event hubs source or HTTP source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: `Azure/Dynamic365/Logs`

Expand All @@ -37,11 +37,11 @@ Follow the [prerequisites](https://learn.microsoft.com/en-us/dynamics365/custome

In this section, you will configure a pipeline for shipping diagnostic logs from Azure Monitor to an Event Hub.

1. Create an Event Hubs namespace as described in step 2 of [Vendor configuration](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/#vendor-configuration). Here, you do not have to create an Event Hub Instance in step 3 since `Microsoft Dynamics 365 Customer Insights` automatically creates the below two Event Hubs:
1. Create an Event Hubs namespace as described in step 2 of [Vendor configuration](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/#vendor-configuration). Here, you do not have to create an Event Hub Instance in step 3 since `Microsoft Dynamics 365 Customer Insights` automatically creates the below two Event Hubs:
* **insight-logs-audit**. It contains audit events.
* **insight-logs-operational**. It contains operational events.
2. Create a [Shared Access Policy](https://docs.microsoft.com/en-us/azure/governance/policy/overview) for the entire namespace with the `Listen` claim or you can use the existing default `RootManageSharedAccessKey` policy. Copy the `Primary key` associated with this policy. For more details, refer to steps 4 and 5 of the [Vendor configuration section](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/#vendor-configuration).
3. Create two Azure Event Hubs Sources using the instructions described [here](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/azure-event-hubs-source/#vendor-configuration). You can add both of them to the same Hosted Collector. Provide `insight-logs-audit` and `insight-logs-operational` as `Event Hubs Instance Name` in the two Azure Event Hubs Sources, respectively.
2. Create a [Shared Access Policy](https://docs.microsoft.com/en-us/azure/governance/policy/overview) for the entire namespace with the `Listen` claim or you can use the existing default `RootManageSharedAccessKey` policy. Copy the `Primary key` associated with this policy. For more details, refer to steps 4 and 5 of the [Vendor configuration section](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/#vendor-configuration).
3. Create two Azure Event Hubs Sources using the instructions described [here](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/#vendor-configuration). You can add both of them to the same Hosted Collector. Provide `insight-logs-audit` and `insight-logs-operational` as `Event Hubs Instance Name` in the two Azure Event Hubs Sources, respectively.
4. To create the Diagnostic settings in the Azure portal, refer to the [Azure documentation](https://learn.microsoft.com/en-us/dynamics365/customer-insights/diagnostics#set-up-diagnostics-with-azure-monitor).
1. Choose Event Hub as the `Resource type`.
1. Select the Event Hub's `Subscription` name, `Resource group` name, and `Resource` name for the destination resource.
Expand Down
Loading