Defender for Storage plan where it store the logs

Naresh Badgujar 0 Reputation points
2024-12-18T05:37:42.1533333+00:00

When we are enabling Defender for Storage plan or other plan -where its store the logs.

we can check the alerts, but to get the alert, defender must be checking some logs, so that logs where it store ? and how to check it ?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,449 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Stanislav Zhelyazkov 25,326 Reputation points MVP
    2024-12-18T07:08:53.35+00:00

    Hi,

    as per Understand malware scanning results:

    • A blob index tag - an index tag with the key Malware scanning scan result (index tags aren't supported in storage accounts with hierarchical namespaces enabled).
    • An Event Grid message - allows you to automate responses to scan results. It requires more configuration. Learn more about setting up Event Grid for malware scanning.
    • A Log Analytics Workspace log entry - by utilizing this method, you can store all scan results in a centralized log repository. This repository is designed for easy querying, making it a powerful tool for tracking and analyzing scan results. Learn more about setting up logging for malware scanning and the Event Grid message structure.
    • A security alert in Defender for Cloud (if malware was detected) - you can read more about Microsoft Defender for Cloud security alerts.

    On that same document you can find information how to view the results on blob index tags. You can check Set up logging for malware scanning if you wish the results to be send to Log Analytics workspace or event grid. On Security alerts and incidents you can find more about Defender for Cloud security alerts.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.