You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1 and 100 virtual machines that run Windows Server.
You need to configure the collection of Windows Security event logs for ingestion to WS1. The solution must meet the following requirements:
• Capture a full user audit trail including user sign-in and user sign-out events.
• Minimize the volume of events.
• Minimize administrative effort.
Which event set should you select?
sapphire
2 weeks, 1 day agorsanx42
6 months agoostralo
7 months, 4 weeks agomayu01
8 months agoTuitor01
4 days, 14 hours agorsanx42
6 months ago