Skip to content
Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation
  • Blog Posts
  • Blog Posts by Category
  • Github Repo
  • Speaks & Events
  • Experts Live Denmark
  • Pictures
    • Pictures Microsoft
    • Pictures Tech Peers
  • About | Morten
    • Contact
    • Disclaimer

Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation

  • Blog Posts
  • Blog Posts by Category
  • Github Repo
  • Speaks & Events
  • Experts Live Denmark
  • Pictures
    • Pictures Microsoft
    • Pictures Tech Peers
  • About | Morten
    • Contact
    • Disclaimer

Morten Knudsen

Collecting CEF Syslogs using Azure Monitor Agent

03/04/202302/04/2023 by Morten Knudsen

This blog will give you insight on how to setup collection of syslogs (CEF) using Linux forwader server using Azure …

Read more

Collecting Syslogs using Azure Monitor Agent

03/04/202302/04/2023 by Morten Knudsen

This blog will give you insight on how to setup collection of syslogs using Linux forwader server using Azure Monitor …

Read more

Tutorial – How to make data transformations using Data Collection Rules?

12/04/202302/04/2023 by Morten Knudsen

This section will show you the steps for setting up data transformations – and how you can do the transformation …

Read more

Master Azure Logging in depth

14/09/202402/04/2023 by Morten Knudsen

I am really passioned about the logging capabilities in M365 Defender and Azure with the power to bring data back from clients, servers, cloud and …

Read more

Orphaned Azure Security Principals Clean-up & Azure Policy Managed Identity Role Assignment Automation

06/02/202306/02/2023 by Morten Knudsen

This blog covers 2 topics : (1) how you can automate clean-up of any orphaned security principal role assignments – …

Read more

Tags Automation, azure, identity not found, managed identity, MicrosoftSecurity, Policy, role assignment, security, unknown

Automate Reporting of Defender for Cloud recommendations & Role Assignments with 35 different views

23/04/202301/02/2023 by Morten Knudsen

Background Recently, I was asked to build a simple reporting-script, which integrates data from Microsoft Defender for Cloud and Azure …

Read more

Tags azure, Defender, DefenderForCloud, MDC, MicrosoftSecurity, security

How to implement a gradual (ring) rollout-process for Microsoft Defender updates

18/03/202315/01/2023 by Morten Knudsen

It is important to ensure that your security posture systems are up-to-date to be able to prevent attacks. Microsoft Defender …

Read more

Tags Antivirus, Defender, DefenderForEndpoint, Endpoint, Gradual, Release, Rollout, Updates

How to save $$$ by storing your Syslog and Defender for Endpoint long-term logs in Azure Data Explorer cluster using Azure Data Factory and Azure Storage Account export – while keeping Kusto query functionalities ?

15/01/202312/01/2023 by Morten Knudsen

This blog is about keeping long-term Sentinel logs, giving you insight to the options today – with great opportunities to …

Read more

Tags adf, adx, azure, cost, log, Loganalytics, Logging, long-term, longterm, retention, Sentinel

Sentinel Alert Rules Management with Add / Update / Remove & Alert Rule Action automation

09/01/202309/01/2023 by Morten Knudsen

Do you want to automate alert rules including creating new alert rules and update existing – with checks every x …

Read more

Tags Alert Rules, Create, Manage, Management, Remove, Sentinel, Update

Real example with 43% cost savings on Sentinel log-costs: How to exclude Syslog log-events from banned IPs using AbuseIPDB-service with integration to firewalls

02/01/202329/12/2022 by Morten Knudsen

This is a real-life example of how I helped reduce the log-cost by 43% for LogAnalytics & Sentinel combined for …

Read more

Tags azure, cost, Loganalytics, optimization, Sentinel, Syslog
Older posts
Newer posts
← Previous Page1 … Page4 Page5 Page6 Next →

About | Morten Knudsen

Triple Microsoft MVP (Security, Azure & Security Copilot)

Microsoft Certified Trainer (1999-2025)

Cloud & Security Architect

Blogger aka.ms/morten

Public speaker

Mentor

Co-founder Experts Live Denmark

Board Member Experts Live Global

  • LinkedIn
  • Bluesky
  • Twitter
  • Mail

Recent Posts

  • Modern Outlook/Teams fails with WebView2 error – seen on Win11 ARM
  • Script: Sentinel Data Lake Table Management
  • How to Enforce Macro Security by running only Excel macros signed with your own public-CA–issued code-signing certificate – stored in Azure Keyvault (HSM)
  • How to Block Upload to WeTransfer, DropBox & Google Drive (but Allowing Download) – using Microsoft Purview Data Loss Prevention (DLP)
  • Tutorial: Integrate AI into your Powershell scripts
Tweets by knudsenmortendk
  • Privacy Policy
  • Terms
  • Contact
© 2026 Blog by Morten Knudsen about Microsoft Security, Azure, M365 & Automation • Built with GeneratePress
Next Page »