How it works...

The preceding query returns a list of the various types of data in your workspace. A cursory review of the various data types could easily indicate which types of data are related to security, as shown in the following screenshot. However, the Security and Audit solution makes use of various other data types in the list, including (but not limited to) Wire Data, DnsEvents, W3CIISLog, and Update:

Figure 6.21

The Security and Audit solution works with data collected from Windows Security Event logs, firewall logs, and AppLocker logs on Windows machines. On cross-platform machines, OMS collects security data from Syslog.

Examples ...

Get Microsoft Operations Management Suite Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.