Collecting logs and data sources
Data collection from VMs is done by installing an agent that is supported by both Linux and Windows. Within Azure, there are different agents that you should be aware of:
- Azure Monitor Agent
- Azure Log Analytics agent (this is known as the legacy agent and will be deprecated after August 2024)
At the time of authoring this book, some features are not supported in Azure Monitor Agent, such as integration into Microsoft Defender for Servers with EDR capabilities. While Azure Monitor Agent supports DCRs, the Log Analytics agent does not. There are also some differences in terms of supported operating systems: https://docs.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview#supported-operating-systems.
You can view the full list of feature differences between the different agents here: https://docs.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview. It should be noted that Azure Monitor Agent is eventually going...