<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does the Azure AD add on retrieve the complete set of sign-in records? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402964#M49182</link>
    <description>&lt;P&gt;Have you tried the Microsoft cloud services app?  It may do what you’re looking for too.&lt;/P&gt;</description>
    <pubDate>Sat, 19 May 2018 12:02:46 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2018-05-19T12:02:46Z</dc:date>
    <item>
      <title>Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402960#M49178</link>
      <description>&lt;P&gt;On the basis of the data I see from our tenant the add on is not retrieving all of the sign in records when compared with the Azure Portal sign in page. &lt;/P&gt;

&lt;P&gt;The number of records loaded appears correlated with the polling frequency set. I have tried 300s (5m), 600s (10m) and 900s  (15m). In each case the number of underlying events that the add on loads appears different. The effect is quite marked. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4973i3D32628F7E7DE8D4/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Query for the chart above:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=liquid_it sourcetype="ms:aad:signin"  
|  timechart span=5m count 
| eval tpm=round(count / 5, 2) 
| fields - count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 17 May 2018 14:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402960#M49178</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-05-17T14:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402961#M49179</link>
      <description>&lt;P&gt;Some further details: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Splunk Enterprise 7.0.2&lt;/LI&gt;
&lt;LI&gt;Set the AAD Reporting add-on to retrieve every 300s&lt;/LI&gt;
&lt;LI&gt;After 24 hours of running am still only getting a subset of the audit records&lt;/LI&gt;
&lt;LI&gt;Can discern no pattern to the missing events; no obvious time boundary issue, no attribute of the events not present in splunk that stands out&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Needless to say this is a deal-breaker. If the audit in Splunk is not complete it is all but useless. &lt;/P&gt;

&lt;P&gt;Not sure how to progress in diagnosing this. &lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 12:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402961#M49179</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-05-18T12:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402962#M49180</link>
      <description>&lt;P&gt;Changed the polling frequency to 600s to see if that makes a difference.&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 07:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402962#M49180</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-05-19T07:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402963#M49181</link>
      <description>&lt;P&gt;Ok, so there is some relationship between the frequency of polling and how many events get ingested. The more frequent the polling the fewer events (the more missing events). The less frequent the polling the more events get ingested for any given period. &lt;/P&gt;

&lt;P&gt;I changed the polling from 300s to 600s and the number of events per minute went up by a factor of 3. &lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 10:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402963#M49181</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-05-19T10:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402964#M49182</link>
      <description>&lt;P&gt;Have you tried the Microsoft cloud services app?  It may do what you’re looking for too.&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 12:02:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402964#M49182</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-05-19T12:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402965#M49183</link>
      <description>&lt;P&gt;Thanks, will try that. Initially I did not think it did the sign-ins, but on closer reading it may do. &lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 06:44:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402965#M49183</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-05-20T06:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402966#M49184</link>
      <description>&lt;P&gt;Version 1.0.3 of the Azure AD Reporting Add-on has some data collection improvements that should address your issue. Also Azure AD logs can be sent to Event Hubs now. The &lt;A href="https://splunkbase.splunk.com/app/3534/"&gt;Azure Monitor Add-on for Splunk&lt;/A&gt; can be used to collect them from an Event Hub.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 17:06:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402966#M49184</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2018-08-09T17:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402967#M49185</link>
      <description>&lt;P&gt;This Microsoft article &lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-reports-latencies#security-reports"&gt;https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-reports-latencies#security-reports&lt;/A&gt;  talks about the latency for sign-ins and audit logs in Azure. The latency is between 2 to 5 mins. My understand would be that the logs will be available in Azure portal (also ready for the API to pull) within 5 mins of the originating event.   So I think setting the polling frequency to &amp;gt;300s should be OK.  However, I have concern about this Add-on using the largest siginDateTime/activityDateTime seen during the query as the checkpoint timestamp. My reasoning is that Azure logs may come in different order, and we will miss some events came in late but their originating event timestamps are before the checkpoint.   &lt;/P&gt;

&lt;P&gt;I have the following scenario in mind:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt; My Signins Input starts at 1:10pm (with polling interval 10 mins) and the current checkpoint is 1:00pm&lt;/LI&gt;
&lt;LI&gt; 1st input/query ran and pulling logs from 1:00pm to 1:10pm.  The Add-on set the largest siginDataTime as the checkpoint.  (Let’s say the largest signin time seen from the query is 1:07pm, now the checkpoint is 1:07pm)&lt;/LI&gt;
&lt;LI&gt; If I have a originating sign-in event happened at 1:06pm but this log is not made available until 1:11pm (5 mins delay). So my 1st query that ran at 1:10pm missed this log and that’s OK as I will expect the next query will pick it up.&lt;/LI&gt;
&lt;LI&gt; Now at 1:20pm my 2nd input ran. This query however just pulled log from 1:07pm (current checkpoint) to 1:20pm. At this point, my 1:06pm sign-in event is going to be skipped.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;As suggested by jconger, the "Azure Monitor Add-on for Splunk" may be the better way to collect near real time from the an Event Hub.&lt;/P&gt;

&lt;P&gt;FYI... I have been trying to collect Azure AD logs (sign-in, audit), Azure AD risk events, as well as Office 365 logs into Splunk. I feel in general the latencies in the Microsoft reporting infrastructure causing lots of confusion/issues on how we can properly schedule our data ingestion without incomplete/duplicate data problem. It makes it harder to use the data for near real time monitoring/reporting solution.  &lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 14:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402967#M49185</guid>
      <dc:creator>swong2</dc:creator>
      <dc:date>2018-08-16T14:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402968#M49186</link>
      <description>&lt;P&gt;Completely agree with your statement:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;the latencies in the Microsoft reporting infrastructure causing lots of confusion/issues on how we can properly schedule our data ingestion without incomplete/duplicate data problem&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 17 Aug 2018 10:52:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402968#M49186</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-08-17T10:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402969#M49187</link>
      <description>&lt;P&gt;Thanks for the suggestion, will try this out. Have set up the event hub and can see activity. Will be interesting to do a side-by-side and see if I get a more complete set of events via this route than the API-based reporting add-on. &lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 10:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402969#M49187</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-08-17T10:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402970#M49188</link>
      <description>&lt;P&gt;Ok, the results are in and on this basis I can see that the Azure AD Reporting Add-on is missing events.&lt;/P&gt;

&lt;P&gt;I set up an alternate ingest pipeline:  AAD --&amp;gt; Event Hub --&amp;gt; Azure function  --&amp;gt; Splunk HEC&lt;/P&gt;

&lt;P&gt;That reliably produces more events than the reporting add-on.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 10:27:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402970#M49188</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-08-31T10:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402971#M49189</link>
      <description>&lt;P&gt;I set up an alternate ingest pipeline: AAD --&amp;gt; Event Hub --&amp;gt; Azure function --&amp;gt; Splunk HEC&lt;/P&gt;

&lt;P&gt;That reliably produces a full set of the events in the graph the new ingest is "aad_audit" and the reporting add-in is shown as "ms:aad:signin". The difference is quite marked.  &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4972iB3F3DA8BC56C1555/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 10:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402971#M49189</guid>
      <dc:creator>raoul</dc:creator>
      <dc:date>2018-08-31T10:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Azure AD add on retrieve the complete set of sign-in records?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402972#M49190</link>
      <description>&lt;P&gt;Here's a simple fix to the app if developer is watching this thread - in the api call add '+and+signinDateTime+le+(current time - delay minutes)'.  So the new filter query will look like:&lt;BR /&gt;
&amp;amp;$filter=signinDateTime+gt+(check point time)+and+signinDateTime+le+(current time - delay minutes)&lt;/P&gt;

&lt;P&gt;With delay minutes set to 5, this will get 99% of the data considering MS's less than 5 minute latency for 99% of events. And if you're making the change, please let the user control the delay minutes.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 10:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-the-Azure-AD-add-on-retrieve-the-complete-set-of-sign-in/m-p/402972#M49190</guid>
      <dc:creator>jijulukose</dc:creator>
      <dc:date>2018-10-25T10:08:22Z</dc:date>
    </item>
  </channel>
</rss>

