All Apps and Add-ons

All Reasons for Authentication Events not imported

kernand0
Loves-to-Learn

First of all, thank you for the app. The setup, import, and event classification is great.

The issue I am having is that authentication events with a reason of "Allow unenrolled user" are not included in the import. I couldn't see anything in the python or within the app to restrict/filter events. Any ideas?

0 Karma

bawood
Path Finder

You are correct, the add-on doesn't do any filtering of events. It simply pulls the raw logs from DUO in their default json format and indexes them. There is some eventyping done for CIM compliance, but that doesn't change the indexed data.

If you have access, or someone else in your org has access to DUO's admin web interface, do you see those events listed there? If so, I'd be interested in knowing that, I haven't heard of any issues like this. I've had the add-on published for a couple of years and it hasn't changed much, but that doesn't mean something hasn't changed on DUO's side. DUO publishes their own Splunk app as well now, so I've been debating whether I should update mine or not.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...