Need help with solution to deploy sentinel in US region and China region

sameer khandar 0 Reputation points
2025-02-10T05:52:12.9666667+00:00

I want to deploy sentinel in US region and China region. is it possible to send logs using DCR rules from China to workspace build in US region or do I need to build 2 workspace separately and send logs from China to US using event Hub .

Incase I configure workspace only in US region and take all logs using DCR from China region , Will that solution work ?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,220 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Sakshi Devkante 735 Reputation points Microsoft Vendor
    2025-02-11T16:06:43.2333333+00:00

    Hello @sameer khandar

    Thank you for reaching out to Microsoft Q&A.

    Unfortunately, there are some limitations on cross-region connectivity with Azure services in China, which are run by local partner 21Vianet. In particular, these data residency and compliance limitations may make it difficult to transport data directly between regions (for example, from China to the US) via DCR. Due to restrictions on cross-region data transfer from the China region, a DCR that gathers logs from China and transmits them straight to a workspace in the US may not perform as intended.

    Go through this thread: https://learn.microsoft.com/en-us/answers/questions/684901/setting-up-sentinel-to-get-logs-from-multiple-regi?page=1#answers

    You can associate multiple workspaces with a single Sentinel instance. For best practices about designing your setup, see Design your Microsoft Sentinel Workspace Architecture.

    You can also view incidents in multiple workspaces at once through the Multiple Workspace View.

    If you configure a Sentinel workspace in the US region and use DCR to collect logs from the China region, this might not work due to the restrictions between the China region and other global Azure regions. The DCR is typically region-specific, and logs collected in China may not be able to be sent directly to a US-based workspace without an intermediary like Event Hub

    The most viable solution is to use Event Hub to transfer logs from the China region to the US region and then ingest them into your US-based Sentinel workspace.

    I hope this clarifies things. Please contact us if you have any additional questions.

    If this answers your query, do click Accept Answer and Yes for "Was this answer helpful". And, if you have any further query do let us know.

    1 person found this answer helpful.

  2. Sameer Khandar 0 Reputation points
    2025-02-13T11:45:54.16+00:00

    Thanks Sakshi for information . Provided information is good enough for me start with solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.