-
Install the Linux OMS Agent
wget https://raw.githubusercontent.com/Microsoft/OMS-Agent-for-Linux/master/installer/scripts/onboard_agent.sh && sh onboard_agent.sh -w {workspace_id_here} -s {workspace_secret_here} -d opinsights.azure.com
-
Add Performance counters to workspace
- Open Data Connectors
- Browse to syslog
- Open Connector
- Click
Open your workspace advanced settings configuration
- Click
Data
>Linux Performance Counters
- Add the following counters
-
Wait for performance counters to be displayed in Azure Sentinel
-
Further KQL queries can be found here
This repository has been archived by the owner on Apr 19, 2022. It is now read-only.