You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1 and 100 virtual machines that run Windows Server.
You need to configure the collection of Windows Security event logs for ingestion to WS1. The solution must meet the following requirements:
• Capture a full user audit trail including user sign-in and user sign-out events.
• Minimize the volume of events.
• Minimize administrative effort.
Which event set should you select?
sapphire
5 months, 3 weeks agorsanx42
11 months, 1 week agoostralo
1 year, 1 month agomayu01
1 year, 1 month agoTuitor01
5 months, 1 week agorsanx42
11 months, 1 week ago