Hi there,
I had followed the installation instructions to install and configure Microsoft Azure Active Directory Reporting Add-on for Splunk on Heavy Forwarder. The sign-in activities log can be collected from Azure AD.
However, about 90% logs are missing while comparing with Azure portal. Does anyone has an idea about it?
Thanks in advance.
Cheers,
Ray
Are you using version 1.0.3? That version has some data collection improvements. Also Azure AD logs can be sent to Event Hubs now. The Azure Monitor Add-on for Splunk can be used to collect them from an Event Hub.
Perhaps a duplicate of my question