<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547363#M91109</link>
    <description>&lt;P&gt;Hi Dave, thanks for the fast response.&lt;/P&gt;&lt;P&gt;I have been given the details from devops for logins, we still need to set permissions etc on the azure side, but expecting an error detailing this, when it does happen.&lt;/P&gt;&lt;P&gt;The version we're using is not the latest, its the one before as we're using it for eventhubs right now, so we cant bump it up.&lt;/P&gt;&lt;P&gt;We're running on S8 and dont use a proxy, proxy is disabled, we do however have URL whitelisting on our firewalls.&lt;/P&gt;&lt;P&gt;Can you please confirm the URLs that are used for obtaining AAD Users?&lt;/P&gt;&lt;P&gt;I've asked devops to check for anything on the azure side.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 12:51:37 GMT</pubDate>
    <dc:creator>JimboSlice</dc:creator>
    <dc:date>2021-04-09T12:51:37Z</dc:date>
    <item>
      <title>microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/472056#M81128</link>
      <description>&lt;P&gt;microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs&lt;/P&gt;

&lt;P&gt;if we look for internal logs , getting below mentioned events frequently , didn't see any issue but still we are not seeing any data.&lt;/P&gt;

&lt;P&gt;2019-12-23 14:44:18,779 DEBUG pid=28967 tid=MainThread file=connectionpool.py:&lt;EM&gt;new_conn:809 | Starting new HTTPS connection (1): graph.microsoft.com&lt;BR /&gt;
2019-12-23 14:44:18,772 INFO pid=28967 tid=MainThread file=setup_util.py:log_info:114 | Proxy is not enabled!&lt;BR /&gt;
2019-12-23 14:44:18,772 DEBUG pid=28967 tid=MainThread file=base_modinput.py:log_debug:286 | _Splunk&lt;/EM&gt; Getting proxy server.&lt;BR /&gt;
2019-12-23 14:44:18,772 DEBUG pid=28967 tid=MainThread file=base_modinput.py:log_debug:286 | &lt;EM&gt;Splunk&lt;/EM&gt; nextLink URL (@odata.nextLink): &lt;A href="https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&amp;amp;$filter=createdDateTime+gt+2019-12-22T14%3a42%3a44.517899Z+and+createdDateTime+le+2019-12-23T14%3a35%3a44.819576Z&amp;amp;$skiptoken=**************************_17000" target="_blank"&gt;https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&amp;amp;$filter=createdDateTime+gt+2019-12-22T14%3a42%3a44.517899Z+and+createdDateTime+le+2019-12-23T14%3a35%3a44.819576Z&amp;amp;$skiptoken=**************************_17000&lt;/A&gt;&lt;BR /&gt;
2019-12-23 14:44:18,134 DEBUG pid=28967 tid=MainThread file=connectionpool.py:_make_request:400 | &lt;A href="https://graph.microsoft.com:443" target="_blank"&gt;https://graph.microsoft.com:443&lt;/A&gt; "GET /beta/auditLogs/signIns?$orderby=createdDateTime&amp;amp;$filter=createdDateTime+gt+2019-12-22T14%3a42%3a44.517899Z+and+createdDateTime+le+2019-12-23T14%3a35%3a44.819576Z&amp;amp;$skiptoken=*****************************_16000 HTTP/1.1" 200 None&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:28:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/472056#M81128</guid>
      <dc:creator>ashikuma</dc:creator>
      <dc:date>2020-09-30T03:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547359#M91107</link>
      <description>&lt;P&gt;Hi, i have the same issue, what was your resolution?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 12:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547359#M91107</guid>
      <dc:creator>JimboSlice</dc:creator>
      <dc:date>2021-04-09T12:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547362#M91108</link>
      <description>&lt;P&gt;1. Are you getting any logs at all from this app? Whether sign ins, users, directory audit, risk detections, or directory devices?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Are you using the latest version of the app?&lt;/P&gt;&lt;P&gt;3. Are you using a proxy in your environment? I see from the message that it is not using a in the app, but if a proxy is blocking your internet access then this could make a problem.&lt;/P&gt;&lt;P&gt;4. Have you double-checked your Tenant ID, Client ID, and Client Secret (the latter two are for your App Registration which must have the required permissions &lt;A href="https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/edit?usp=sharing" target="_blank"&gt;https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/edit?usp=sharing&lt;/A&gt; )&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 12:47:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547362#M91108</guid>
      <dc:creator>dave_null</dc:creator>
      <dc:date>2021-04-09T12:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547363#M91109</link>
      <description>&lt;P&gt;Hi Dave, thanks for the fast response.&lt;/P&gt;&lt;P&gt;I have been given the details from devops for logins, we still need to set permissions etc on the azure side, but expecting an error detailing this, when it does happen.&lt;/P&gt;&lt;P&gt;The version we're using is not the latest, its the one before as we're using it for eventhubs right now, so we cant bump it up.&lt;/P&gt;&lt;P&gt;We're running on S8 and dont use a proxy, proxy is disabled, we do however have URL whitelisting on our firewalls.&lt;/P&gt;&lt;P&gt;Can you please confirm the URLs that are used for obtaining AAD Users?&lt;/P&gt;&lt;P&gt;I've asked devops to check for anything on the azure side.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 12:51:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547363#M91109</guid>
      <dc:creator>JimboSlice</dc:creator>
      <dc:date>2021-04-09T12:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: microsoft azure add-on for Splunk is unable to pull ad risky sign-on logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547365#M91110</link>
      <description>&lt;P&gt;OK so he added the permission, now seen this error on a one-off basis:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-04-09 13:56:10,464 ERROR pid=136881 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/aob_py3/modinput_wrapper/base_modinput.py", line 128, in stream_events&lt;BR /&gt;self.collect_events(ew)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/MS_AAD_user.py", line 76, in collect_events&lt;BR /&gt;input_module.collect_events(self, ew)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/input_module_MS_AAD_user.py", line 36, in collect_events&lt;BR /&gt;users_response = azutils.get_items_batch(helper, access_token, url)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_azure_utils/utils.py", line 55, in get_items_batch&lt;BR /&gt;raise e&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_azure_utils/utils.py", line 49, in get_items_batch&lt;BR /&gt;r.raise_for_status()&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/aob_py3/requests/models.py", line 940, in raise_for_status&lt;BR /&gt;raise HTTPError(http_error_msg, response=self)&lt;BR /&gt;requests.exceptions.HTTPError: 403 Client Error: Forbidden for url: &lt;A href="https://graph.microsoft.com/beta/users/" target="_blank"&gt;https://graph.microsoft.com/beta/users/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 13:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/microsoft-azure-add-on-for-Splunk-is-unable-to-pull-ad-risky/m-p/547365#M91110</guid>
      <dc:creator>JimboSlice</dc:creator>
      <dc:date>2021-04-09T13:02:59Z</dc:date>
    </item>
  </channel>
</rss>

