Microsoft Azure Event Hubs is a data and event processing service for Microsoft Azure. The integration between USM Anywhere and Azure Event Hubs enables the Azure Sensor to receive and process information from an event hub so that you can manage them in your USM Anywhere environment.
The Azure Sensor can process different types of logs sent through Azure Event Hubs, including but not limited to the following:
- Azure Active Directory (AD) logs, including audit logs and sign-in logs
- Azure Monitor logs
- Azure SQL Database logs
- Microsoft Defender Advanced Threat Protection (ATP) logs
Stream Logs to Azure Event Hubs
Before configuring the Azure Event Hubs integration in USM Anywhere, you must stream the logs you want to be analyzed to an event hub. Make sure to stream your logs to the same Event Hubs namespace, because each Azure Sensor can only collect from a single event hub.
To stream logs to Azure Event Hubs
- Log in to the Azure portal.
- Create an event hub. See Microsoft Azure Quickstart: Create an event hub using Azure portal for instructions.
- Go to the Event Hubs namespace you just created and click Shared access policies in the sidebar.
- Create or edit a policy, and then select Manage, Send, and Listen. Streaming to Event Hubs requires these permissions.
Copy the connection string listed in the policy.
You need to enter this string when configuring the Event Hubs connection in USM Anywhere.
Configure streaming for the logs you want to collect. For example:
- Azure AD logs: See Stream Azure Active Directory Logs to an Azure Event Hub for instructions from Microsoft.
- Azure Monitor logs: See Stream Activity Log to Event Hub for instructions from Microsoft.
- Azure SQL Database logs: See Set up auditing for your database for instructions from Microsoft. Make sure to select Event Hub as the destination.
- Microsoft Defender ATP logs: See Configure Microsoft Defender ATP to stream Advanced Hunting events to your Azure Event Hubs for instructions from Microsoft.
Set Up Azure Event Hubs Connection in USM Anywhere
After completing the initial setup of your Azure Event Hubs, return to your USM Anywhere Sensors page to enable the Event Hubs connection in USM Anywhere.
To enable Azure Event Hubs in USM Anywhere
- Go to the Sensors page and open the Azure Sensor.
Click the Configurations tab.
Complete the three fields:
- Event Hub Name: The name of the event hub created during initial setup.
- Event Hub Connection String: A string containing unique configuration data about your Event Hubs implementation. This string was discovered during the previous procedure.
- Event Hub Consumer Group: The name of your Event Hubs consumer group. You can locate this name by opening your Event Hubs overview in the Azure portal and scrolling to the bottom of the page.
(Optional.) Select Process generic events to collect events for which USM Anywhere currently does not have a plugin. These events will display as "GENERIC event" under Activity > Events.
- Click Save.
- Click the Event Hub tab to see the connectivity status.
Viewing Azure Event Hubs Connectivity in USM Anywhere
The Event Hub tab on the Azure Sensor page provides a glimpse into the health of your sensor's connection to Azure Event Hubs. This page contains the name of your event hub, its connectivity status, and the number of events being processed by USM Anywhere.
To view your Azure Event Hubs connection
- Go to the Sensors page and open your Azure Sensor.
- Click the Event Hub tab.
These are the connectivity statuses you may see:
- Connecting: Azure Event Hubs is currently connecting to the sensor.
- Processing: Azure Event Hubs is successfully connected.
- Shutting Down: Azure Event Hubs has begun the shutdown process to allow a different event hub to connect to the sensor.
- Shutdown: The sensor is not currently connected to an event hub.
- Error: The connection has experienced an error.