You plan to connect an external solution that will send Common Event Format (CEF) messages to Azure Sentinel.
You need to deploy the log forwarder.
Which three actions should you perform in sequence? To answer, move the appropriate actions form the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation:

Reference:
For CEF ingestion, Microsoft Sentinel uses a Linux "log forwarder" that runs the Log Analytics agent (OMS agent) and a syslog daemon (rsyslog/syslog-ng). The documented deployment flow is: first install the Log Analytics agent on the forwarder and connect it to your Sentinel workspace (Workspace ID/Key). Next, configure the agent to listen on TCP/UDP port 25226 -the port the OMS agent uses to receive CEF- translated syslog messages locally-and forward them to the connected workspace (this forwarding is inherent once the agent is connected). Then configure the syslog daemon to receive the external product's CEF events on the chosen syslog port (commonly 514) and forward them locally to 127.0.0.1:25226 . Finally, restart rsyslog/syslog-ng and the OMS agent to apply changes. You do not forward events "directly to Sentinel" from syslog; the agent handles transport to the workspace. An OMS Gateway is only required when the forwarder has no direct Internet access and isn't part of the standard, minimal-effort path. This sequence ensures reliable, supported ingestion of CEF messages into Microsoft Sentinel with the least administrative overhead.