All Apps and Add-ons

All Reasons for Authentication Events not imported

kernand0
Loves-to-Learn

First of all, thank you for the app. The setup, import, and event classification is great.

The issue I am having is that authentication events with a reason of "Allow unenrolled user" are not included in the import. I couldn't see anything in the python or within the app to restrict/filter events. Any ideas?

0 Karma

bawood
Path Finder

You are correct, the add-on doesn't do any filtering of events. It simply pulls the raw logs from DUO in their default json format and indexes them. There is some eventyping done for CIM compliance, but that doesn't change the indexed data.

If you have access, or someone else in your org has access to DUO's admin web interface, do you see those events listed there? If so, I'd be interested in knowing that, I haven't heard of any issues like this. I've had the add-on published for a couple of years and it hasn't changed much, but that doesn't mean something hasn't changed on DUO's side. DUO publishes their own Splunk app as well now, so I've been debating whether I should update mine or not.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...