Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
missing_linux_example
Summary
The documentation page demonstrates a subtle Windows bias by consistently listing Windows Security Events and Windows Events as primary log sources, and by referencing the Azure Monitoring Agent (AMA) specifically for Windows VMs without mentioning Linux VM log collection methods or Linux-specific agent configuration. There are no explicit Linux or macOS examples, nor are Linux collection patterns or tools described, despite the fact that Syslog and CEF are mentioned as data sources. The guidance for log splitting and agent usage is Windows-centric, and Linux parity is not addressed.
Recommendations
  • Include explicit examples and guidance for collecting logs from Linux VMs, such as configuring AMA or legacy agents for Linux, and how to route Linux security and syslog events to workspaces.
  • Mention Linux-specific log types (e.g., auth.log, syslog, auditd) alongside Windows Security Events when listing data sources.
  • Provide parity in agent configuration instructions, showing both Windows and Linux steps for splitting logs between workspaces.
  • Reference Linux diagnostic settings and data collection patterns where relevant, not just Windows.
  • Clarify that Microsoft Sentinel supports both Windows and Linux sources, and link to Linux-specific documentation.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-12 00:00 #99 completed Clean Clean
2026-01-11 06:20 #98 completed Biased Biased
2026-01-10 00:00 #92 completed Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean