OLD WIKI STEPS FOR SIEM SETUP ON AZURE - Pratiksha-Marane/duplo-docs GitHub Wiki
This document will describe how to setup siem on azure based duplo portal
Repo: https://github.com/duplocloud-internal/duplo-templates/tree/main
-
Create "compliance" tenant under default infra.
-
Deploy template siem/master/azure/siem-template-azure.json using scribe.
-
Get the IP of SIEM host deployed at #2 and update reverse proxy.
-
Create a new tenant in user infra.
-
Deploy agent using template siem/agents/ossec-dockernative.json as daemon set under new tenant.
Note: Create tenant per infra and deploy daemon set under it.