Skip to content

Latest commit

 

History

History
76 lines (53 loc) · 4.66 KB

security-center-ata-integration.md

File metadata and controls

76 lines (53 loc) · 4.66 KB
title description services documentationcenter author manager editor ms.assetid ms.service ms.devlang ms.topic ms.tgt_pltfrm ms.workload ms.date ms.author
Connecting Microsoft Advanced Threat Analytics to Azure Security Center | Microsoft Docs
Learn how Azure Security Center integrates with Microsoft Advanced Threat Analytics.
security-center
na
YuriDio
MBaldwin
5d80bf91-16c3-40b3-82fc-e0805e6708db
security-center
na
article
na
na
10/13/2017
yurid

Connecting Microsoft Advanced Threat Analytics to Azure Security Center

This document helps you to configure the integration between Microsoft Advanced Threat Analytics and Azure Security Center.

Why add Advanced Threat Analytics data?

Advanced Threat Analytics (ATA) is an on-premises platform that helps detect suspicious user behaviors. When connected, you are able to view suspicious actions detected by ATA in Security Center. This integration enables you to view, correlate, and investigate all security alerts related to your hybrid cloud workloads in Security Center.

How do I configure this integration?

Assuming that you already have ATA installed, and working properly on-premises, follow these steps to configure this integration:

  1. Log on to the ATA Center, and access the ATA portal.

  2. Click Syslog server in the left pane.

    Syslog server

  3. In the Syslog server endpoint field, type 127.0.0.7 (it must be this address), and type 5114 on the port (recommended). While the port number is a recommendation, any unique port should work. Leave all other options as is, and click Save.

  4. Click Notifications in the left pane, and enable all the Syslog notifications (recommended) as shown in the following image:

    Notifications

  5. Click Save.

  6. Open Security Center dashboard.

  7. On the left pane, click Security Solutions.

  8. Under Advanced Threat Analytics, click ADD.

    ATA

  9. Go to the last step, and click Download agent.

    ATA

  10. In the Add new non-Azure computer page, select the workspace.

    Non-Azure

  11. In the Direct Agent page, download the appropriate Windows agent, and take notes of the Workspace ID and Primary Key.

    Direct agent

  12. Install this agent in the ATA Center. During the installation, make sure to select the option Connect the agent to Azure Log Analytics (OMS), and provide the workspace ID, and primary key when requested.

Once you finish the installation, the integration is completed, and you will be able to see new alerts sent from ATA to Security Center in Security Alerts and Search. The solution appears in the Security Solutions page, under Connected solutions.

Next steps

In this document, you learned how to connect Microsoft ATA to Security Center. To learn more about Security Center, see the following articles: