From 1a1b94ff36bf54b6dea106527fcf810186d1d9cd Mon Sep 17 00:00:00 2001 From: ImranHabib <47118050+joinimran@users.noreply.github.com> Date: Mon, 27 May 2019 23:16:21 +0500 Subject: [PATCH] Update windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md changes commit. Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../collect-wip-audit-event-logs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md b/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md index 1f21a222aa..b13fc3c4ca 100644 --- a/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md +++ b/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md @@ -167,7 +167,7 @@ Use Windows Event Forwarding to collect and aggregate your WIP audit events. You You can collect audit logs using Azure Monitor. See [Windows event log data sources in Azure Monitor.](https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs) **To view the WIP events in Azure Monitor** -1. Use existing or create new Log Analytics Workspace. +1. Use an existing or create a new Log Analytics workspace. 2. In Log Analytics->Advanced Settings, go to Data, in Windows Event Logs, add logs to receive: ```