cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L1 Bithead

On your 3.x tenant, go to:  https://<tenant_url>/auditing (This brings you to the Management Audit Logs)

Note: There is no dataset dedicated to receiving any sort of events from the Broker VM itself.

 

The best practice would be the SIEM admin to check the https://<tenant_url>/configuration/broker-vms/brokers UI every Monday morning to see if an upgrade is available or a reboot is required to apply an update which is applied automatically.

 

For monitoring health of data ingestions, first ensure Data Ingestion Monitoring is enabled in https://<tenant_url>/configuration/general; then create correlation rules to monitor these ingestion metrics:

Who rated this post