Alsid Syslog/Sentinel proxy

Last updated: 2020-12-23

This template creates and configures a Syslog server with an onboarded Azure Sentinel Agent for a specified workspace.

This Azure Resource Manager (ARM) template was created by a member of the community and not by Microsoft. Each ARM template is licensed to you under a licence agreement by its owner, not Microsoft. Microsoft is not responsible for ARM templates provided and licensed by community members and does not screen for security, compatibility or performance. Community ARM templates are not supported under any Microsoft support programme or service, and are made available AS IS without warranty of any kind.

Parameters

Parameter Name Description
vmName Hostname of the virtual machine.
vmAdminUserName User name of the administrator account of the virtual machine.
vmAdminPassword Password of the administrator account of the virtual machine
dnsLabelPrefix DNS Label for the Public IP. Must be lowercase. It should match with the following regular expression: ^[a-z][a-z0-9-]{1,61}[a-z0-9]$ or it will raise an error.
workspaceId The ID of the log analytics workspace where you want to forward the logs. To find it, go to your workspace and you will have both the workspace ID and Primary key in the 'Agent management' tab.
primaryKey The key to authenticate to the log analytics workspace where you want to forward the logs. To find it, go to your workspace and you will have both the workspace ID and Primary key in the 'Agent management' tab.
vmUbuntuOSVersion Version of the Ubuntu OS.
vmSize Size of the virtual machine's disk
location Location where resources should be deployed.
_artifactsLocation The base URI where artifacts required by this template are located including a trailing '/'
_artifactsLocationSasToken The sasToken required to access _artifactsLocation. When the template is deployed using the accompanying scripts, a sasToken will be automatically generated. Use the defaultValue if the staging location is not secured.

Use the template

PowerShell

New-AzResourceGroup -Name <resource-group-name> -Location <resource-group-location> #use this command when you need to create a new resource group for your deployment
New-AzResourceGroupDeployment -ResourceGroupName <resource-group-name> -TemplateUri https://raw.githubusercontent.com/Azure/azure-quickstart-templates/master/alsid-syslog-proxy/azuredeploy.json
Installing and configuring Azure PowerShell

Command line

az group create --name <resource-group-name> --location <resource-group-location> #use this command when you need to create a new resource group for your deployment
az group deployment create --resource-group <my-resource-group> --template-uri https://raw.githubusercontent.com/Azure/azure-quickstart-templates/master/alsid-syslog-proxy/azuredeploy.json
Installing and configuring the Azure cross-platform command-line interface