Skip to main content

CollectorsCloud Collectors Administration Guide

Migrate the Azure Activity Logs Cloud Collector

The Azure Activity Logs Cloud Collector enables you to ingest logs into the Exabeam Security Operations Platform. If you previously used the Azure Cloud Connector and want to take advantage of the Cloud Collectors service, migration to the new Cloud Collector is recommended. Before you migrate, consider the following:

  • The ingestion method now leverages Azure Event Hub as the transport mechanism versus the previously supported API.

  • License Requirements: No additional license is required. The Cloud Collectors service is included with your existing license.

  • Required Azure Subscriptions: The following table displays minimum Azure subscriptions required per feature.

    Feature

    Minimum Azure Subscription

    Ingestion from EventHub

    EventHub Standard or Premium

  • SaaS Cloud Connectors Support: Both the SaaS Cloud Connectors and the new Cloud Collectors environments can run in parallel.

The following table indicates the Azure Cloud Connector endpoints that map to the new Cloud Collector Azure Activity Logs.

Legacy Connector

Legacy Endpoint

New Collector

Azure

Discovered endpoints per subscription ID

For example:

  • Activity Log - [Subscription ID: 55cfdd3d-a90e-42a3-5a0c-55f704541a75] - [Subscription Name: Prod (NCC LMT)]

  • Activity Log - [Subscription ID: 1234d2b8-a1cd-4f2d-a887-c12345e9d193] - [Subscription Name: DSV (TBB)]

  • Activity Log - [Subscription ID: ca101a23-eaa2-4d8f-b0a9-a62dcd3c1c61] - [Subscription Name: Prod (MBB TIP)]

  • Activity Log - [Subscription ID: 68fadac8-00ca-4906-8c29-5108abe12054] - [Subscription Name: NonProd (TBB LMB)]

Azure Activity Logs

When you are ready to migrate:

  1. Stop the specific Activity Log endpoints for the Azure Cloud Connector. For example, Activity Log - [Subscription ID: 68fadac8-00ca-4906-8c29-5108abe12054] - [Subscription Name: NonProd (TBB LMB)]

    activity_logs_legacy_endpoint_updated.png
  2. Wait for the running tasks to complete. The user interface indicates the time required for task completion.

  3. Complete the prerequisites to configure the Azure Activity Logs Cloud Collector.

  4. Follow the steps to configure the Azure Activity Logs Cloud Collector.

  5. Use the same consumer group name that you used for the Azure Cloud Connector, while configuring the Azure Activity Logs Cloud Collector.