All Apps and Add-ons

All Reasons for Authentication Events not imported

kernand0
Loves-to-Learn

First of all, thank you for the app. The setup, import, and event classification is great.

The issue I am having is that authentication events with a reason of "Allow unenrolled user" are not included in the import. I couldn't see anything in the python or within the app to restrict/filter events. Any ideas?

0 Karma

bawood
Path Finder

You are correct, the add-on doesn't do any filtering of events. It simply pulls the raw logs from DUO in their default json format and indexes them. There is some eventyping done for CIM compliance, but that doesn't change the indexed data.

If you have access, or someone else in your org has access to DUO's admin web interface, do you see those events listed there? If so, I'd be interested in knowing that, I haven't heard of any issues like this. I've had the add-on published for a couple of years and it hasn't changed much, but that doesn't mean something hasn't changed on DUO's side. DUO publishes their own Splunk app as well now, so I've been debating whether I should update mine or not.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...