<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to connect with and retrieve logs from Azure Active Directory? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180172#M36121</link>
    <description>&lt;P&gt;I believe you can with azure diagnostic storage.   There are two add-ons have been published in apps.splunk.com.  You will likely have to work with support to get the AD logs sent to the diagnostic storage then you should be gravy.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1586/"&gt;https://splunkbase.splunk.com/app/1586/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/900/"&gt;https://splunkbase.splunk.com/app/900/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Nov 2015 20:31:20 GMT</pubDate>
    <dc:creator>bmacias84</dc:creator>
    <dc:date>2015-11-11T20:31:20Z</dc:date>
    <item>
      <title>How to connect with and retrieve logs from Azure Active Directory?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180169#M36118</link>
      <description>&lt;P&gt;Hi to everyone&lt;/P&gt;

&lt;P&gt;I need to get logs from Azure AD (Active Directory for Microsoft Azure). Do you know how to do this?&lt;/P&gt;

&lt;P&gt;I'll be grateful for any help&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 19:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180169#M36118</guid>
      <dc:creator>rubeniturrieta</dc:creator>
      <dc:date>2015-08-18T19:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect with and retrieve logs from Azure Active Directory?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180170#M36119</link>
      <description>&lt;P&gt;Hi! Did you work this problem out? We're wondering about the same thing, where I'm currently investigating how to get data from Azure AD and ADFS into Splunk. Is it possible to install a Splunk forwarder "on" Azure, or is it better to have Azure send its data to, and write to file on, some other machine running a Splunk forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 14:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180170#M36119</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2015-11-10T14:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect with and retrieve logs from Azure Active Directory?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180171#M36120</link>
      <description>&lt;P&gt;Hi hettervi. No, i don't have this problem solved, i gave up &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 15:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180171#M36120</guid>
      <dc:creator>rubeniturrieta</dc:creator>
      <dc:date>2015-11-11T15:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect with and retrieve logs from Azure Active Directory?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180172#M36121</link>
      <description>&lt;P&gt;I believe you can with azure diagnostic storage.   There are two add-ons have been published in apps.splunk.com.  You will likely have to work with support to get the AD logs sent to the diagnostic storage then you should be gravy.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1586/"&gt;https://splunkbase.splunk.com/app/1586/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/900/"&gt;https://splunkbase.splunk.com/app/900/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 20:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180172#M36121</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-11-11T20:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect with and retrieve logs from Azure Active Directory?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180173#M36122</link>
      <description>&lt;P&gt;None of these apps are supported for 6.3.1, the Azure Diagnostics app haven't been updated since 2012, but they might work. Do you have any experience with these apps yourself? Do they access the API of Azure AD, or do you still have to forward your data from Azure AD to some server for them to work? I'm currently trying to figure out a way to make use of Windows Event Forwarder for forwarding of data from Azure AD, but I'm not sure if this is the way to go.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 09:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180173#M36122</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2015-11-12T09:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect with and retrieve logs from Azure Active Directory?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180174#M36123</link>
      <description>&lt;P&gt;no I have not had any experience with theses apps, but they do use the Azure API.  Both apps should work since they are modular inputs which poll the API from a forwarder in your env.   All you should need to do is contact Azure support to send your logs to there Diagnostics storage for you to retrieve from there API.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 21:32:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-connect-with-and-retrieve-logs-from-Azure-Active/m-p/180174#M36123</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-11-12T21:32:57Z</dc:date>
    </item>
  </channel>
</rss>

