<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: O365 Disable MFA Analytics in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677749#M18685</link>
    <description>&lt;P&gt;the above query not working but when i Operation!="Disable Strong Authentication."&amp;nbsp; getting enabled mfa users list.&lt;BR /&gt;&lt;BR /&gt;i have already ingested the Splunk logs and completed the macro creation&lt;/P&gt;</description>
    <pubDate>Fri, 16 Feb 2024 06:58:10 GMT</pubDate>
    <dc:creator>saskn</dc:creator>
    <dc:date>2024-02-16T06:58:10Z</dc:date>
    <item>
      <title>O365 Disable MFA Analytics</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677748#M18684</link>
      <description>&lt;P&gt;&lt;A href="https://research.splunk.com/cloud/c783dd98-c703-4252-9e8a-f19d9f5c949e/" target="_blank" rel="noopener"&gt;https://research.splunk.com/cloud/c783dd98-c703-4252-9e8a-f19d9f5c949e/&lt;BR /&gt;&lt;BR /&gt;when i give this command Operation!="Disable Strong Authentication."&amp;nbsp; i am getting the MFA enabled users details.&lt;BR /&gt;&lt;BR /&gt;But when the below query is executed i am not getting any output.&lt;BR /&gt;&lt;BR /&gt;Can some one help me in sharing some docs&lt;/A&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="1011.9px" height="241px"&gt;&lt;PRE&gt;`o365_management_activity` Operation="Disable Strong Authentication." 
| stats count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation UserId ResultStatus object 
| rename UserType AS user_type, Operation AS action, UserId AS src_user, object AS user, ResultStatus AS result 
| `security_content_ctime(firstTime)` 
| `security_content_ctime(lastTime)` 
| `o365_disable_mfa_filter`&lt;/PRE&gt;&lt;PRE&gt;as per the&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 16 Feb 2024 06:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677748#M18684</guid>
      <dc:creator>saskn</dc:creator>
      <dc:date>2024-02-16T06:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Disable MFA Analytics</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677749#M18685</link>
      <description>&lt;P&gt;the above query not working but when i Operation!="Disable Strong Authentication."&amp;nbsp; getting enabled mfa users list.&lt;BR /&gt;&lt;BR /&gt;i have already ingested the Splunk logs and completed the macro creation&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 06:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677749#M18685</guid>
      <dc:creator>saskn</dc:creator>
      <dc:date>2024-02-16T06:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: O365 Disable MFA Analytics</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677768#M18691</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264986"&gt;@saskn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If the query works when&amp;nbsp;&lt;SPAN&gt;Operation!="Disable Strong Authentication.", it shows no user disabled MFA. Normally, you have no results if all users are using MFA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 08:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/O365-Disable-MFA-Analytics/m-p/677768#M18691</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-02-16T08:58:07Z</dc:date>
    </item>
  </channel>
</rss>

