All Apps and Add-ons

All Reasons for Authentication Events not imported

kernand0
Loves-to-Learn

First of all, thank you for the app. The setup, import, and event classification is great.

The issue I am having is that authentication events with a reason of "Allow unenrolled user" are not included in the import. I couldn't see anything in the python or within the app to restrict/filter events. Any ideas?

0 Karma

bawood
Path Finder

You are correct, the add-on doesn't do any filtering of events. It simply pulls the raw logs from DUO in their default json format and indexes them. There is some eventyping done for CIM compliance, but that doesn't change the indexed data.

If you have access, or someone else in your org has access to DUO's admin web interface, do you see those events listed there? If so, I'd be interested in knowing that, I haven't heard of any issues like this. I've had the add-on published for a couple of years and it hasn't changed much, but that doesn't mean something hasn't changed on DUO's side. DUO publishes their own Splunk app as well now, so I've been debating whether I should update mine or not.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...