All Apps and Add-ons

Azure AD log missing

cmtse
New Member

Hi there,

I had followed the installation instructions to install and configure Microsoft Azure Active Directory Reporting Add-on for Splunk on Heavy Forwarder. The sign-in activities log can be collected from Azure AD.

However, about 90% logs are missing while comparing with Azure portal. Does anyone has an idea about it?
Thanks in advance.

Cheers,
Ray

0 Karma

jconger
Splunk Employee
Splunk Employee

Are you using version 1.0.3? That version has some data collection improvements. Also Azure AD logs can be sent to Event Hubs now. The Azure Monitor Add-on for Splunk can be used to collect them from an Event Hub.

0 Karma

raoul
Path Finder

Perhaps a duplicate of my question

0 Karma
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...