MCAS log ingestion deployment modes( Log collector vs MDE)

%3CLINGO-SUB%20id%3D%22lingo-sub-2752250%22%20slang%3D%22en-US%22%3EMCAS%20log%20ingestion%20deployment%20modes(%20Log%20collector%20vs%20MDE)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2752250%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20techies%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20you%20all%20doing%20well%20and%20keeping%20safe%20during%20this%20unprecedented%20timings!!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20couple%20of%20queries%20regarding%20log%20deployment%20modes.%20Please%20help%20me%20understand.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20part%20of%20transition%20we%20have%20been%20requested%20to%20support%20for%20one%20of%20our%20clients.%20In%20the%20current%20ecosystem%20log%20ingestion%20is%20being%20happened%20through%20native%20MDE%20integration%20and%20via%20log%20collectors(%20Docker%20image%20on%20Linux%20in%20Azure)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20When%20we%20are%20able%20to%20discover%20the%20data%20from%20MDE%2C%20why%20should%20we%20have%20log%20collector%20deployment%20inplace%3F%20I%20believe%20with%20the%20help%20of%20log%20collectors%20only%2C%20we%20can%20able%20to%20replicate%20the%20cloud%20discovery%20resource%20details(%20statistics%20for%20platform%20security%20i.e%20storage%20account%20transactions%20)%20please%20correct%20me%20if%20i%20am%20wrong.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20If%20we%20ingest%20the%20data%20from%20both%20mde%20and%20through%20log%20collector%20servers%20will%20it%20be%20treated%20as%20redundant%20logs%20from%20MCAS%20side%3F%20how%20will%20it%20be%20processed%20the%20data%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3.%20Log%20collectors%20are%20showing%20offline%20since%20Sep4th%202021.%20But%20last%20parsed%20log%20is%20showing%20as%20sep%2014th%3F%20So%20there%20is%2010%20days%20of%20delay%20in%20processing%20the%20data%20from%20log%20collectors%20to%20MCAS%3F%20Why%20it%20is%20taking%2010%20days%20time%20period%20because%2C%20we%20would%20be%20in%20a%20blind%20spot%20from%20security%20standpoint%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20somebody%20please%20help%20me%20understand%20the%20above%20queries%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooking%20forward%20to%20hearing%20for%20these%20queries%20please%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%2C%3C%2FP%3E%3CP%3EMahesh.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2752250%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20Discovery%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hello techies,

 

Hope you all doing well and keeping safe during this unprecedented timings!!

 

I have couple of queries regarding log deployment modes. Please help me understand.

 

As part of transition we have been requested to support for one of our clients. In the current ecosystem log ingestion is being happened through native MDE integration and via log collectors( Docker image on Linux in Azure)

 

1. When we are able to discover the data from MDE, why should we have log collector deployment inplace? I believe with the help of log collectors only, we can able to replicate the cloud discovery resource details( statistics for platform security i.e storage account transactions ) please correct me if i am wrong.

 

2. If we ingest the data from both mde and through log collector servers will it be treated as redundant logs from MCAS side? how will it be processed the data?

 

3. Log collectors are showing offline since Sep4th 2021. But last parsed log is showing as sep 14th? So there is 10 days of delay in processing the data from log collectors to MCAS? Why it is taking 10 days time period because, we would be in a blind spot from security standpoint?

 

Can somebody please help me understand the above queries?

 

Looking forward to hearing for these queries please?

 

Thank you,

Mahesh.

 

 

 

0 Replies
www.000webhost.com