SlideShare a Scribd company logo
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Session 8
AZ-104: Microsoft Azure
Administrator
1
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
AzureTalk Core Team
2
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Today’s Session Speaker
Niraj Kumar
AzureTalk Founder
Enterprise Architect, MCT
3
Ashish Raj
AzureTalk Core Team
DevOps Architect, MCT
Vipin Jha
AzureTalk Core Team
Consultant, MCT
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
AZ-104 Skills Measured
• Manage Azure identities and governance (15-20%)
• Deploy and manage Azure compute resources (25-30%)
• Implement and manage storage (10-15%)
• Configure and manage virtual networking (30-35%)
• Monitor and back up Azure resources (10-15%)
4
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
AZ-104 Prerequisites
5
Understanding of
• Operating systems
• Virtualization
• Network configuration
• Active Directory
• Resilience and disaster recovery
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Agenda
6
• Azure Monitor
• Azure Alerts
• Log Analytics
• Network Watcher
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Monitor
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Monitor
8
Monitoring options available in Azure
• Azure Security Center
• Azure Application Insights
• Azure Sentinel
• Azure Monitor
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Security Center
9
• Identify and address risks and threats
• Security of infrastructure from a centralized location
• On-premises or in cloud
• Monitor security of workloads
• Collects security-related data from VM and other resources
• Monitor health of resources and implement
recommendations
• Ease configuration of your security
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Security Center
10
Analyses different components of environment
• Data security
• Network security
• Identity and access
• Application security
• Recommends how to address issues and risks that it has
uncovered
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Security Center
11
Advanced Cloud Defense
• Adaptive application controls
• Just in time(JIT) VM access
• Adaptive network hardening
• File Integrity Monitoring
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Security Center
12
• Respond to threats faster & automated
• Create a playbook by configuring a logic app
• Playbooks are automated procedures run against
alerts
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Application Insights
13
• Monitor, manage performance of applications
• Gathers information related to performance, errors
& exceptions in applications
• Diagnose cause of problems that affect application
• Monitor release pipelines for application
• Improve your development lifecycle
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Application Insights
14
How It works
• Set up an Application Insights resource in Azure
portal
• Install an instrumentation package in application
• Package will monitor application and send log data
to Log Analytics workspace
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Sentinel
15
• Security information event management (SIEM)
• Security orchestration automated response
(SOAR) solution
• Collect data across users, devices, applications,
• On-premises , multiple clouds
• Detect & Investigate threats with artificial
intelligence
• Respond to incidents rapidly
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Monitor
16
• Service for collecting, combining, and analyzing data from different
sources
• Detect and diagnose issues across applications and dependencies with
Application Insights
• Correlate infrastructure issues with Azure Monitor for VMs and Azure
Monitor for Containers
• Drill into monitoring data with Log Analytics for Deep diagnostics
• Support alerts and automated actions
• Create visualizations with Azure dashboards and workbooks
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Monitor
17
Collects data from a range of components
• Application data
• Operating system data
• Azure resource data
• Azure subscription data
• Azure tenant data
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Monitor
18
Reference : Microsoft Docs
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Monitor Health Of VM
19
Default Basic Metrics for Azure VMs
• CPU usage
• Network traffic
• OS disk usage
• Boot success
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Monitor Health Of VM
20
• To get a Full set of metrics install two tools on VM
• Azure Diagnostics extension
• Log Analytics agent
• Both tools are available for Windows and Linux
• Tools need storage account to save data that they collect
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Question 1
In Azure Security Center Which tool allows to automate
responses to alerts?
a) Playbooks
b) Adaptive controls
c) FIM
d) Advanced cloud defense
21
https://q.azureezy.com/1
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Question 1
In Azure Security Center Which tool allows to automate
responses to alerts?
a) Playbooks
b) Adaptive controls
c) FIM
d) Advanced cloud defense
22
https://q.azureezy.com/1
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Alerts
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Azure Alerts
24
• Proactively notify when conditions found in
monitoring data
• Identify and address issues before users of system
notice them
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Key Attributes Of Alert Rule
25
• Target Resource
• VM, Storage account, Scale Set
• Signal
• Metric, Activity Log, Application Insights
• Criteria (Percentage CPU > 70%)
• Alert Name
• Alert Description
• Severity
• 0 Critical, 1 Error, 2 Warning, 3 Informational, 4 Verbose
• Action
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Action Group
26
• Collection of notification preferences defined
• Azure Monitor and Service Health alerts use action
groups to notify users that an alert has been
triggered
• Various alerts may use the same action group or
different action groups depending on the user's
requirements.
• Configure up to 2,000 action groups in a
subscription
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Available Actions
27
• Send an email or SMS message
• Create an Azure app push notification
• Make a voice call to a number
• Call an Azure function or Trigger a logic app
• Send a notification to a webhook
• Create an ITSM ticket
• Use a runbook (to restart a VM, or scale a VM up or down)
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Question 2
Action group in Azure Alert is a collection of notification
preferences.
a) True
b) False
28
https://q.azureezy.com/2
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Question 2
Action group in Azure Alert is a collection of notification
preferences.
a) True
b) False
29
https://q.azureezy.com/2
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Log Analytics
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Log Analytics
31
• Collects telemetry from Windows and Linux VM
• From any cloud, on-premises machines, and those monitored
by SCOM
• Sends collected data to Log Analytics workspace in Azure
Monitor
• Supports insights and other services in Azure Monitor
• Azure Monitor for VMs,
• Azure Security Center
• Azure Automation
• No cost for Log Analytics agent, charges for data ingested
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Log Analytics Data collected
32
• Windows Event logs
• Syslog Linux event logging system
• Performance Numerical values measuring
performance of different aspects of OS and
workloads
• IIS logs
• Custom logs Events from text files on both
Windows and Linux computers
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Log Analytics Agent Installation
33
• Azure VM
• Azure Monitor can enable agents at scale
• Azure Security Center can provision the Log Analytics Agent
• VM extension for Windows or Linux
• Azure portal
• Windows VM on-premises or in another cloud
• Manually from command line
• Azure Automation DSC
• Resource Manager template with Azure Stack
• Linux virtual machine on-premises or in another cloud
• Manually wrapper-script hosted on GitHub
• SCOM
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Network Watcher
34
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Network Watcher
35
• Central place to diagnose health of Azure Networks
• Two categories:
• Monitoring Tools
• Diagnostic Tools
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Network Watcher Monitoring Tools
36
Monitoring Tools:
• Topology
• Connection Monitor
• Network Performance Monitor
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Network Watcher Topology
37
Reference : Microsoft Docs
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Network Watcher Diagnostic Tools
38
• IP Flow Verify
• Next Hop
• Effective Security Rules
• Packet Capture
• Connection Troubleshoot
• VPN Troubleshoot
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
IP Flow Verify
39
• Checks if a packet is allowed or denied to or from
a VM
• Based on 5-tuple information
• Specify
• Local and Remote port,
• Protocol (TCP or UDP),
• Local IP, Remote IP,
• VM, and VM’s NIC
• NSG name of rule that denied packet is returned
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Next Hop
40
• Provides next hop from target VM to destination IP
address
• How a packet gets from a VM to any destination
• Specify source VM /network adapter/IP address, and
destination IP address
• Tool determines packet's destination
• Diagnose problems caused by incorrect routing
tables
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Effective Security Rules
41
• Displays all effective NSG rules applied to a network
interface
• Choose a VM and its network adapter
• Tool displays all NSG rules that apply to that adapter
• Also spot vulnerabilities for VM caused by unnecessary
open ports
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Packet Capture
42
• Record all of packets sent to and from a VM
• VM extension through Network Watcher and automatically
with packet capture session
• Limit is 100 packet capture sessions per region
• Overall limit is 10,000
• Limits are for the number of sessions only, not saved
captures
• Save packets captured in Azure Storage or locally on
computer
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Connection Troubleshoot
43
• Check TCP connection from a VM to a VM, FQDN, URI, or IPv4 address
• Connection successful information:
• Latency in milliseconds
• Number of probe packets sent
• Number of hops in the complete route to destination
• Connection unsuccessful shows Fault Details:
• Failed because of high CPU utilization
• Failed because of high memory utilization
• GuestFirewall blocked by a firewall outside Azure
• DNSResolution destination IP address couldn't be resolved
• NetworkSecurityRule blocked by an NSG
• UserDefinedRoute incorrect user route in a routing table
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
VPN Troubleshoot
44
• Diagnoses health of virtual network gateway or
connection
• Multiple gateways or connections can be
troubleshooted simultaneously
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Question 3
To check latency issues on the network, which Azure
Network Watcher tool we can use?
a) Connection Troubleshoot
b) IP Flow Verify
c) Next Hop
d) Security Group View
45
https://q.azureezy.com/3
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Question 3
To check latency issues on the network, which Azure
Network Watcher tool we can use?
a) Connection Troubleshoot
b) IP Flow Verify
c) Next Hop
d) Security Group View
46
https://q.azureezy.com/3
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Break
47
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
Demo
1. Create and configure an Azure Log Analytics workspace
and Azure Automation-based solutions
2. Review default monitoring settings of Azure VM
3. Configure Azure VM diagnostic settings
4. Review Azure Monitor functionality
5. Review Azure Log Analytics functionality
https://azureezy.com
© 2020 AzureEzy and AzureTalk. All rights reserved!
50
https://bharatguru.in
https://azureezy.com
Thanks!https://azureezy.com/az-104
https://t.me/AzureTalk
https://youtube.com/c/AzureTalk
https://www.linkedin.com/in/nirajkum/
https://www.linkedin.com/in/vipinkumarjha/
https://www.linkedin.com/in/ashishrajsrivastava
https://azuredevopspro.com
https://youtube.com/c/AshishRajSrivastava
@AshishRajS

More Related Content

PDF
Az 104 session 5: Azure networking
PDF
Az 104 session 6 azure networking part2
PDF
Az 104 session 3 azure compute
PDF
Az 104 session 4: azure storage
PDF
Az 104 session 2 implement and manage azure webapps and container
PDF
Microsoft Azure - Introduction to microsoft's public cloud
PDF
Az 900 session 2-core azure services
PPTX
Azure Storage
Az 104 session 5: Azure networking
Az 104 session 6 azure networking part2
Az 104 session 3 azure compute
Az 104 session 4: azure storage
Az 104 session 2 implement and manage azure webapps and container
Microsoft Azure - Introduction to microsoft's public cloud
Az 900 session 2-core azure services
Azure Storage

What's hot (20)

PPTX
Azure WAF
PPTX
Azure Availability Options
PDF
Microsoft Azure Active Directory
PPTX
AWS Certified Solutions Architect Professional Course S1-S5
PPTX
Azure active directory
PDF
Az 900 Session 3 Security, privacy, compliance, trust, pricing, SLA and Lifec...
PDF
Microsoft az-104 Dumps
PPTX
Azure virtual network
PDF
20190226 AWS Black Belt Online Seminar Amazon WorkSpaces
PPTX
Azure Fundamentals || AZ-900
PDF
AWS Summit Seoul 2023 | 서버리스, 이제는 데이터 분석에서 활용해요!
PPTX
Azure key vault
PPTX
Understanding Azure Disaster Recovery
PDF
20191105 AWS Black Belt Online Seminar Amazon Route 53 Hosted Zone
PPTX
Azure AD Presentation - @ BITPro - Ajay
PDF
AWS Connectivity, VPC Design and Security Pro Tips
PPTX
Azure Governance
PPTX
Azure Networking - The First Technical Challenge
PDF
AWS CodeCommit, CodeDeploy & CodePipeline
PDF
AZ-204 : Implement Azure security
Azure WAF
Azure Availability Options
Microsoft Azure Active Directory
AWS Certified Solutions Architect Professional Course S1-S5
Azure active directory
Az 900 Session 3 Security, privacy, compliance, trust, pricing, SLA and Lifec...
Microsoft az-104 Dumps
Azure virtual network
20190226 AWS Black Belt Online Seminar Amazon WorkSpaces
Azure Fundamentals || AZ-900
AWS Summit Seoul 2023 | 서버리스, 이제는 데이터 분석에서 활용해요!
Azure key vault
Understanding Azure Disaster Recovery
20191105 AWS Black Belt Online Seminar Amazon Route 53 Hosted Zone
Azure AD Presentation - @ BITPro - Ajay
AWS Connectivity, VPC Design and Security Pro Tips
Azure Governance
Azure Networking - The First Technical Challenge
AWS CodeCommit, CodeDeploy & CodePipeline
AZ-204 : Implement Azure security
Ad

Similar to Az 104 session 8 azure monitoring (20)

PPTX
AZ-303 Episode 15.pptx ( Good for Training)
PDF
AZ-204: Monitor, Troubleshoot & Optimize Azure Solutions
PDF
UpdateConf 2018: Monitoring real-life Azure applications: When to use what an...
PPTX
NVS_Sentinel
PDF
Monitoring real-life Azure applications: When to use what and why
PPTX
Full stack monitoring across apps & infrastructure with Azure Monitor
PDF
Gill C. Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 2...
PPTX
Monitor Cloud Resources using Alerts & Insights
PDF
Azure governance v4.0
PDF
Different monitoring options for cloud native integration solutions
PDF
Monitoring advanced Azure PaaS workloads in the enterprise - Level: 200
PDF
Azure Low Lands 2018: Monitoring real life Azure applications when to use wha...
PPTX
Azure Security and Management
PPTX
TechTalksUtah-Sentinel-20191108.pptx
PPTX
Azure Resource Monitoring cloud talk_20161128
PDF
Microsoft Azure Cloud Services
PDF
FAUG Jyväskylä 28.5.2019 - Azure Monitoring
PPTX
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
PDF
Azure Incident Response Cheat Sheet.pdf
PDF
7.habits.every.azure.admin.must.have.v082020
AZ-303 Episode 15.pptx ( Good for Training)
AZ-204: Monitor, Troubleshoot & Optimize Azure Solutions
UpdateConf 2018: Monitoring real-life Azure applications: When to use what an...
NVS_Sentinel
Monitoring real-life Azure applications: When to use what and why
Full stack monitoring across apps & infrastructure with Azure Monitor
Gill C. Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 2...
Monitor Cloud Resources using Alerts & Insights
Azure governance v4.0
Different monitoring options for cloud native integration solutions
Monitoring advanced Azure PaaS workloads in the enterprise - Level: 200
Azure Low Lands 2018: Monitoring real life Azure applications when to use wha...
Azure Security and Management
TechTalksUtah-Sentinel-20191108.pptx
Azure Resource Monitoring cloud talk_20161128
Microsoft Azure Cloud Services
FAUG Jyväskylä 28.5.2019 - Azure Monitoring
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Azure Incident Response Cheat Sheet.pdf
7.habits.every.azure.admin.must.have.v082020
Ad

More from AzureEzy1 (6)

PDF
AZ-204: Connect to and consume Azure services and third-party services - Part 1
PDF
Develop for Azure storage
PDF
Develop Azure compute solutions Part - 2
PDF
AZ-400: Define and implement a continuous delivery and release management str...
PDF
AZ-400: Define and implement continuous integration – Part 2
PDF
AZ-400 Session 1: Facilitate communication and collaboration
AZ-204: Connect to and consume Azure services and third-party services - Part 1
Develop for Azure storage
Develop Azure compute solutions Part - 2
AZ-400: Define and implement a continuous delivery and release management str...
AZ-400: Define and implement continuous integration – Part 2
AZ-400 Session 1: Facilitate communication and collaboration

Recently uploaded (20)

PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
Approach and Philosophy of On baking technology
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
1. Introduction to Computer Programming.pptx
PDF
1 - Historical Antecedents, Social Consideration.pdf
PPTX
A Presentation on Touch Screen Technology
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
Mushroom cultivation and it's methods.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PDF
Getting Started with Data Integration: FME Form 101
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Approach and Philosophy of On baking technology
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
1. Introduction to Computer Programming.pptx
1 - Historical Antecedents, Social Consideration.pdf
A Presentation on Touch Screen Technology
SOPHOS-XG Firewall Administrator PPT.pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Group 1 Presentation -Planning and Decision Making .pptx
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Encapsulation theory and applications.pdf
Hindi spoken digit analysis for native and non-native speakers
NewMind AI Weekly Chronicles - August'25-Week II
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
Mushroom cultivation and it's methods.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Heart disease approach using modified random forest and particle swarm optimi...
Getting Started with Data Integration: FME Form 101

Az 104 session 8 azure monitoring

  • 1. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Session 8 AZ-104: Microsoft Azure Administrator 1
  • 2. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! AzureTalk Core Team 2
  • 3. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Today’s Session Speaker Niraj Kumar AzureTalk Founder Enterprise Architect, MCT 3 Ashish Raj AzureTalk Core Team DevOps Architect, MCT Vipin Jha AzureTalk Core Team Consultant, MCT
  • 4. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! AZ-104 Skills Measured • Manage Azure identities and governance (15-20%) • Deploy and manage Azure compute resources (25-30%) • Implement and manage storage (10-15%) • Configure and manage virtual networking (30-35%) • Monitor and back up Azure resources (10-15%) 4
  • 5. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! AZ-104 Prerequisites 5 Understanding of • Operating systems • Virtualization • Network configuration • Active Directory • Resilience and disaster recovery
  • 6. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Agenda 6 • Azure Monitor • Azure Alerts • Log Analytics • Network Watcher
  • 7. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Monitor
  • 8. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Monitor 8 Monitoring options available in Azure • Azure Security Center • Azure Application Insights • Azure Sentinel • Azure Monitor
  • 9. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Security Center 9 • Identify and address risks and threats • Security of infrastructure from a centralized location • On-premises or in cloud • Monitor security of workloads • Collects security-related data from VM and other resources • Monitor health of resources and implement recommendations • Ease configuration of your security
  • 10. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Security Center 10 Analyses different components of environment • Data security • Network security • Identity and access • Application security • Recommends how to address issues and risks that it has uncovered
  • 11. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Security Center 11 Advanced Cloud Defense • Adaptive application controls • Just in time(JIT) VM access • Adaptive network hardening • File Integrity Monitoring
  • 12. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Security Center 12 • Respond to threats faster & automated • Create a playbook by configuring a logic app • Playbooks are automated procedures run against alerts
  • 13. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Application Insights 13 • Monitor, manage performance of applications • Gathers information related to performance, errors & exceptions in applications • Diagnose cause of problems that affect application • Monitor release pipelines for application • Improve your development lifecycle
  • 14. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Application Insights 14 How It works • Set up an Application Insights resource in Azure portal • Install an instrumentation package in application • Package will monitor application and send log data to Log Analytics workspace
  • 15. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Sentinel 15 • Security information event management (SIEM) • Security orchestration automated response (SOAR) solution • Collect data across users, devices, applications, • On-premises , multiple clouds • Detect & Investigate threats with artificial intelligence • Respond to incidents rapidly
  • 16. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Monitor 16 • Service for collecting, combining, and analyzing data from different sources • Detect and diagnose issues across applications and dependencies with Application Insights • Correlate infrastructure issues with Azure Monitor for VMs and Azure Monitor for Containers • Drill into monitoring data with Log Analytics for Deep diagnostics • Support alerts and automated actions • Create visualizations with Azure dashboards and workbooks
  • 17. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Monitor 17 Collects data from a range of components • Application data • Operating system data • Azure resource data • Azure subscription data • Azure tenant data
  • 18. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Monitor 18 Reference : Microsoft Docs
  • 19. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Monitor Health Of VM 19 Default Basic Metrics for Azure VMs • CPU usage • Network traffic • OS disk usage • Boot success
  • 20. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Monitor Health Of VM 20 • To get a Full set of metrics install two tools on VM • Azure Diagnostics extension • Log Analytics agent • Both tools are available for Windows and Linux • Tools need storage account to save data that they collect
  • 21. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Question 1 In Azure Security Center Which tool allows to automate responses to alerts? a) Playbooks b) Adaptive controls c) FIM d) Advanced cloud defense 21 https://q.azureezy.com/1
  • 22. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Question 1 In Azure Security Center Which tool allows to automate responses to alerts? a) Playbooks b) Adaptive controls c) FIM d) Advanced cloud defense 22 https://q.azureezy.com/1
  • 23. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Alerts
  • 24. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Azure Alerts 24 • Proactively notify when conditions found in monitoring data • Identify and address issues before users of system notice them
  • 25. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Key Attributes Of Alert Rule 25 • Target Resource • VM, Storage account, Scale Set • Signal • Metric, Activity Log, Application Insights • Criteria (Percentage CPU > 70%) • Alert Name • Alert Description • Severity • 0 Critical, 1 Error, 2 Warning, 3 Informational, 4 Verbose • Action
  • 26. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Action Group 26 • Collection of notification preferences defined • Azure Monitor and Service Health alerts use action groups to notify users that an alert has been triggered • Various alerts may use the same action group or different action groups depending on the user's requirements. • Configure up to 2,000 action groups in a subscription
  • 27. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Available Actions 27 • Send an email or SMS message • Create an Azure app push notification • Make a voice call to a number • Call an Azure function or Trigger a logic app • Send a notification to a webhook • Create an ITSM ticket • Use a runbook (to restart a VM, or scale a VM up or down)
  • 28. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Question 2 Action group in Azure Alert is a collection of notification preferences. a) True b) False 28 https://q.azureezy.com/2
  • 29. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Question 2 Action group in Azure Alert is a collection of notification preferences. a) True b) False 29 https://q.azureezy.com/2
  • 30. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Log Analytics
  • 31. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Log Analytics 31 • Collects telemetry from Windows and Linux VM • From any cloud, on-premises machines, and those monitored by SCOM • Sends collected data to Log Analytics workspace in Azure Monitor • Supports insights and other services in Azure Monitor • Azure Monitor for VMs, • Azure Security Center • Azure Automation • No cost for Log Analytics agent, charges for data ingested
  • 32. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Log Analytics Data collected 32 • Windows Event logs • Syslog Linux event logging system • Performance Numerical values measuring performance of different aspects of OS and workloads • IIS logs • Custom logs Events from text files on both Windows and Linux computers
  • 33. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Log Analytics Agent Installation 33 • Azure VM • Azure Monitor can enable agents at scale • Azure Security Center can provision the Log Analytics Agent • VM extension for Windows or Linux • Azure portal • Windows VM on-premises or in another cloud • Manually from command line • Azure Automation DSC • Resource Manager template with Azure Stack • Linux virtual machine on-premises or in another cloud • Manually wrapper-script hosted on GitHub • SCOM
  • 34. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Network Watcher 34
  • 35. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Network Watcher 35 • Central place to diagnose health of Azure Networks • Two categories: • Monitoring Tools • Diagnostic Tools
  • 36. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Network Watcher Monitoring Tools 36 Monitoring Tools: • Topology • Connection Monitor • Network Performance Monitor
  • 37. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Network Watcher Topology 37 Reference : Microsoft Docs
  • 38. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Network Watcher Diagnostic Tools 38 • IP Flow Verify • Next Hop • Effective Security Rules • Packet Capture • Connection Troubleshoot • VPN Troubleshoot
  • 39. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! IP Flow Verify 39 • Checks if a packet is allowed or denied to or from a VM • Based on 5-tuple information • Specify • Local and Remote port, • Protocol (TCP or UDP), • Local IP, Remote IP, • VM, and VM’s NIC • NSG name of rule that denied packet is returned
  • 40. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Next Hop 40 • Provides next hop from target VM to destination IP address • How a packet gets from a VM to any destination • Specify source VM /network adapter/IP address, and destination IP address • Tool determines packet's destination • Diagnose problems caused by incorrect routing tables
  • 41. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Effective Security Rules 41 • Displays all effective NSG rules applied to a network interface • Choose a VM and its network adapter • Tool displays all NSG rules that apply to that adapter • Also spot vulnerabilities for VM caused by unnecessary open ports
  • 42. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Packet Capture 42 • Record all of packets sent to and from a VM • VM extension through Network Watcher and automatically with packet capture session • Limit is 100 packet capture sessions per region • Overall limit is 10,000 • Limits are for the number of sessions only, not saved captures • Save packets captured in Azure Storage or locally on computer
  • 43. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Connection Troubleshoot 43 • Check TCP connection from a VM to a VM, FQDN, URI, or IPv4 address • Connection successful information: • Latency in milliseconds • Number of probe packets sent • Number of hops in the complete route to destination • Connection unsuccessful shows Fault Details: • Failed because of high CPU utilization • Failed because of high memory utilization • GuestFirewall blocked by a firewall outside Azure • DNSResolution destination IP address couldn't be resolved • NetworkSecurityRule blocked by an NSG • UserDefinedRoute incorrect user route in a routing table
  • 44. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! VPN Troubleshoot 44 • Diagnoses health of virtual network gateway or connection • Multiple gateways or connections can be troubleshooted simultaneously
  • 45. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Question 3 To check latency issues on the network, which Azure Network Watcher tool we can use? a) Connection Troubleshoot b) IP Flow Verify c) Next Hop d) Security Group View 45 https://q.azureezy.com/3
  • 46. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Question 3 To check latency issues on the network, which Azure Network Watcher tool we can use? a) Connection Troubleshoot b) IP Flow Verify c) Next Hop d) Security Group View 46 https://q.azureezy.com/3
  • 47. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Break 47
  • 48. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! Demo 1. Create and configure an Azure Log Analytics workspace and Azure Automation-based solutions 2. Review default monitoring settings of Azure VM 3. Configure Azure VM diagnostic settings 4. Review Azure Monitor functionality 5. Review Azure Log Analytics functionality
  • 49. https://azureezy.com © 2020 AzureEzy and AzureTalk. All rights reserved! 50 https://bharatguru.in https://azureezy.com Thanks!https://azureezy.com/az-104 https://t.me/AzureTalk https://youtube.com/c/AzureTalk https://www.linkedin.com/in/nirajkum/ https://www.linkedin.com/in/vipinkumarjha/ https://www.linkedin.com/in/ashishrajsrivastava https://azuredevopspro.com https://youtube.com/c/AshishRajSrivastava @AshishRajS