Azure Honeypot & Sentinel SIEM Project (Part 2): Creating and Collecting Custom Logs on Azure

Опубликовано: 10 Февраль 2022
на канале: Sezcurity
562
15

This is part 2 of the project.
In this video I run a Powershell script to collect source IP addresses of failed login attempts and pass them through an online API to return geolocation data which is then written to a log file. I also create a custom log in Log Analytics Workspaces to collect geolocation data.

#######################################################
Relevant Resources

Log exporter script - https://github.com/joshmadakor1/Senti...

IP Geolocation website - https://ipgeolocation.io/