Route Azure SQL audit logs
With the new capability to route Azure SQL audit logs to multiple Log Analytics workspaces, you can now send the same audit data to different teams or tools. For example, one workspace for security monitoring (e.g. via Microsoft Sentinel) and another for application-level analytics.
Set it up by first enabling auditing to a primary workspace, then add separate diagnostic settings to push logs to additional workspaces. This separation helps maintain clean separation of duties, improves compliance and governance, and gives each team the log access they need without overlap.
www.ChironIT.com
ChironIT AzureSQL AzureMonitor LogAnalytics CloudSecurity DataSecurity
Next post: Microsoft Entra Global Secure Access