How to configure a new DCR to ingest to an existing Custom Log table?

Callens Nico 0 Reputation points
2024-10-31T13:04:33.53+00:00

Hi All,

I am currently migrating existing syslog logfeeds running over Logstash pipelines with the "microsoft-logstash-output-azure-loganalytics" output module to Logstash pipelines with the "microsoft-sentinel-log-analytics-logstash-output-plugin" output module with DCR. I would like to ingest the migrated flow into the existing Custom Log table, but I did not found any solution so far in the Azure WebGUI. Is there a way to accomplish this? Possible by the web shell?

Thanks for sharing your experience.

Regards,

Nico

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,337 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,172 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pauline Mbabu 560 Reputation points Microsoft Employee
    2024-11-20T07:09:26.4066667+00:00

    Hello Callens Nico,

    To ingest the migrated flow into an existing custom Log Table, you can follow the guidance given on this doc https://github.com/Azure/Azure-Sentinel/blob/master/DataConnectors/microsoft-sentinel-log-analytics-logstash-output-plugin/README.md

    In case you are still having challenges with the plug-in please open a support ticket here - https://ms.portal.azure.com/#create/Microsoft.Support As the service type select- "Azure Sentinel"

    I hope this helps to answer your question.
    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.