Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions blog-service/2024/12-31.md
Original file line number Diff line number Diff line change
Expand Up @@ -161,17 +161,17 @@ We're excited to introduce Copilot, an AI-powered assistant that accelerates log

### December 02, 2024 (Apps)

#### Microsoft Defender for Cloud
#### Azure Security - Defender for Cloud

We're excited to introduce the new Microsoft Defender for Cloud app for Sumo Logic. This app helps you to collect the alerts, security recommendation, and regulatory compliance logs using the Sumo Logic Cloud-to-Cloud Azure Event Hub Source and by configuring the continuous export using the Event Hub instance details in the Azure portal. Key features of the Microsoft Defender for Cloud app include:
We're excited to introduce the new Azure Security - Defender for Cloud app for Sumo Logic. This app helps you to collect the alerts, security recommendation, and regulatory compliance logs using the Sumo Logic Cloud-to-Cloud Azure Event Hub Source and by configuring the continuous export using the Event Hub instance details in the Azure portal. Key features of the Azure Security - Defender for Cloud app include:

- Gain real-time visibility into security alerts across your Azure environment, categorized by severity (High, Medium, Low, and Informational).
- Monitor trends in alert activity over time to identify spikes and recurring threats.
- Leverage detailed alert summaries and remediation steps for effective threat mitigation.
- Track compliance performance across critical standards, including FedRAMP, PCI DSS 4, CIS Azure Foundations, and Microsoft Cloud Security Benchmark.
- Analyze threats by categories like data exfiltration, unauthorized access, and account breaches.

Explore our technical documentation [here](/docs/integrations/microsoft-azure/microsoft-defender-for-cloud/) to learn how to set up and use the Microsoft Defender for Cloud app for Sumo Logic.
Explore our technical documentation [here](/docs/integrations/microsoft-azure/azure-security-defender-for-cloud/) to learn how to set up and use the Azure Security - Defender for Cloud app for Sumo Logic.

### December 02, 2024 (Apps)

Expand Down
5 changes: 3 additions & 2 deletions cid-redirects.json
Original file line number Diff line number Diff line change
Expand Up @@ -1862,7 +1862,7 @@
"/cid/1963": "/docs/integrations/sumo-apps/enterprise-audit",
"/cid/1964": "/docs/integrations/security-threat-detection/f5-big-ip-ltm",
"/cid/1965": "/docs/integrations/security-threat-detection/netskope",
"/cid/19665": "/docs/integrations/microsoft-azure/microsoft-defender-for-cloud",
"/cid/19665": "/docs/integrations/microsoft-azure/azure-security-defender-for-cloud",
"/cid/1966": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/carbon-black-cloud-source",
"/cid/1987": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-endpoint-security-source",
"/cid/1996": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sysdig-secure-source",
Expand Down Expand Up @@ -4287,5 +4287,6 @@
"/docs/manage/manage-subscription/create-manage-orgs-service-providers": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
"/docs/manage/manage-subscription/create-manage-orgs-flex": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
"/docs/manage/manage-subscription/manage-org-settings": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
"/docs/integrations/amazon-aws/elastic-load-balancing": "/docs/integrations/amazon-aws/classic-load-balancer"
"/docs/integrations/amazon-aws/elastic-load-balancing": "/docs/integrations/amazon-aws/classic-load-balancer",
"/docs/integrations/microsoft-azure/microsoft-defender-for-cloud": "/docs/integrations/microsoft-azure/azure-security-defender-for-cloud"
}
Original file line number Diff line number Diff line change
@@ -1,16 +1,16 @@
---
id: microsoft-defender-for-cloud
title: Microsoft Defender for Cloud
description: Learn about the Sumo Logic collection process for the Microsoft Defender for Cloud service.
id: azure-security-defender-for-cloud
title: Azure Security - Defender for Cloud
description: Learn about the Sumo Logic collection process for the Azure Security - Defender for Cloud service.
---

import useBaseUrl from '@docusaurus/useBaseUrl';

<img src={useBaseUrl('img/integrations/microsoft-azure/microsoft-defender-for-cloud.png')} alt="Thumbnail icon" width="50"/>

The Sumo Logic app for Microsoft Defender for Cloud is a powerful solution designed to provide Azure cloud security analysts with actionable insights into their cloud security posture. By integrating with Microsoft Defender for Cloud, this app delivers advanced monitoring, alerting, and compliance tracking capabilities through purpose-built dashboards tailored to meet the needs of security teams.
The Sumo Logic app for Azure Security - Defender for Cloud is a powerful solution designed to provide Azure cloud security analysts with actionable insights into their cloud security posture. By integrating with Azure Security - Defender for Cloud, this app delivers advanced monitoring, alerting, and compliance tracking capabilities through purpose-built dashboards tailored to meet the needs of security teams.

Key features of the Microsoft Defender for Cloud app include:
Key features of the Azure Security - Defender for Cloud app include:

- Gain real-time visibility into security alerts across your Azure environment, categorized by severity (High, Medium, Low, and Informational).
- Monitor trends in alert activity over time to identify spikes and recurring threats.
Expand All @@ -25,12 +25,12 @@ Key features of the Microsoft Defender for Cloud app include:
- Identify areas requiring immediate action to ensure regulatory adherence for your Azure resources.

:::info
This app includes [built-in monitors](#microsoft-defender-for-cloud-monitors). For details on creating custom monitors, refer to [Create monitors for Microsoft Defender for Cloud app](#create-monitors-for-microsoft-defender-for-cloud-app).
This app includes [built-in monitors](#azure-security---defender-for-cloud-monitors). For details on creating custom monitors, refer to [Create monitors for Azure Security Defender for Cloud app](#create-monitors-for-azure-security---defender-for-cloud-app).
:::

## Log types

The Microsoft Defender for Cloud app uses the following logs:
The Azure Security - Defender for Cloud app uses the following logs:

* [Alerts](https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts)
* [Security recommendations](https://learn.microsoft.com/en-us/azure/defender-for-cloud/review-security-recommendations)
Expand All @@ -41,7 +41,7 @@ The Microsoft Defender for Cloud app uses the following logs:
To forward Microsoft Defender events to Sumo Logic, you can set up an efficient pipeline: **Microsoft Defender** > **Event Hub** > **Sumo Logic (Hosted Collector)**. This setup ensures that security events from Microsoft Defender are seamlessly ingested into Sumo Logic for monitoring and analysis.

1. **[Create a Sumo Logic Azure Event Hub Source](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/)**. Configure an Event Hub source to receive events from the Azure platform. This will act as the endpoint for the data pipeline.
1. **[Set up continuous export in Azure](https://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export)**. Within the Azure portal, configure the Microsoft Defender for Cloud to export its security events to the Event Hub instance created in the previous step. Continuous export ensures that the events such as alerts, recommendations, and regulatory compliance updates are forwarded in near real-time.
1. **[Set up continuous export in Azure](https://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export)**. Within the Azure portal, configure the Azure Security - Defender for Cloud to export its security events to the Event Hub instance created in the previous step. Continuous export ensures that the events such as alerts, recommendations, and regulatory compliance updates are forwarded in near real-time.

## Sample log messages

Expand Down Expand Up @@ -308,13 +308,13 @@ _sourceCategory=azure/defender "Microsoft.Security/regulatoryComplianceStandard
| fields - _count
```

## Installing the Microsoft Defender for Cloud app
## Installing the Azure Security - Defender for Cloud app

import AppInstall from '../../reuse/apps/app-install.md';

<AppInstall/>

## Viewing the Microsoft Defender for Cloud app
## Viewing the Azure Security - Defender for Cloud app

import ViewDashboards from '../../reuse/apps/view-dashboards.md';

Expand Down Expand Up @@ -348,13 +348,13 @@ Detailed remediation steps are included in the Top Action Plans, providing clear

<br/><img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Microsoft-Defender-for-Cloud/Microsoft-Defender-for-Cloud-Security-Recommendations.png' alt="Microsoft-Defender-for-Cloud-Security-Recommendations" />

## Create monitors for Microsoft Defender for Cloud app
## Create monitors for Azure Security - Defender for Cloud app

import CreateMonitors from '../../reuse/apps/create-monitors.md';

<CreateMonitors/>

### Microsoft Defender for Cloud monitors
### Azure Security - Defender for Cloud monitors

| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition |
|:--|:--|:--|:--|
Expand Down Expand Up @@ -386,13 +386,13 @@ If you are not receiving any alerts from the Microsoft Defender to the Event Hub
There may be a delay in forwarding alerts from Microsoft Defender to the Event Hub instance. If you experience significant delays, reach out to Azure Support for assistance.
:::

## Upgrade/Downgrade the Microsoft Defender for Cloud app (Optional)
## Upgrade/Downgrade the Azure Security - Defender for Cloud app (Optional)

import AppUpdate from '../../reuse/apps/app-update.md';

<AppUpdate/>

## Uninstalling the Microsoft Defender for Cloud app (Optional)
## Uninstalling the Azure Security - Defender for Cloud app (Optional)

import AppUninstall from '../../reuse/apps/app-uninstall.md';

Expand Down
12 changes: 6 additions & 6 deletions docs/integrations/microsoft-azure/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -261,6 +261,12 @@ This guide has documentation for all of the apps that Sumo Logic provides for Mi
<p>A guide to the Sumo Logic integration for Azure Relay.</p>
</div>
</div>
<div className="box smallbox card">
<div className="container">
<a href="/docs/integrations/microsoft-azure/azure-security-defender-for-cloud"><img src={useBaseUrl('img/integrations/microsoft-azure/microsoft-defender-for-cloud.png')} alt="thumbnail icon" width="75"/><h4>Azure Security - Defender for Cloud</h4></a>
<p>Learn about the Sumo Logic collection process for the Azure Security - Defender for Cloud service.</p>
</div>
</div>
<div className="box smallbox card">
<div className="container">
<img src={useBaseUrl('img/integrations/microsoft-azure/azure-service-bus.png')} alt="Thumbnail icon" width="60"/>
Expand Down Expand Up @@ -317,12 +323,6 @@ This guide has documentation for all of the apps that Sumo Logic provides for Mi
<p>A guide to the Sumo Logic app for Azure Kubernetes Service Control Plane.</p>
</div>
</div>
<div className="box smallbox card">
<div className="container">
<a href="/docs/integrations/microsoft-azure/microsoft-defender-for-cloud"><img src={useBaseUrl('img/integrations/microsoft-azure/microsoft-defender-for-cloud.png')} alt="thumbnail icon" width="75"/><h4>Microsoft Defender for Cloud</h4></a>
<p>Learn about the Sumo Logic collection process for the Microsoft Defender for Cloud service.</p>
</div>
</div>
<div className="box smallbox card">
<div className="container">
<img src={useBaseUrl('img/integrations/microsoft-azure/network-watcher.png')} alt="Thumbnail icon" width="50"/>
Expand Down
Loading