All Apps and Add-ons

Azure Active Directory Stops

jaxjohnny2000
Builder

I updated the inputs.conf with additional threads (8) and start by shell = false. The data only seems to come in once we restart splunk after that, nothing.

sourcetype="o365:management:activity" Workload=AzureActiveDirectory

What else can I check to see if this is setup correctly?

0 Karma

hok2010
New Member

im facing the same problem, no NSG changes was done in any recent.

only problem is workload "azureactivedirectory" is not reporting and rest  workloads are pulling results perfectly fine.

0 Karma

jaxjohnny2000
Builder

My apologies for not updating this. We found the issue was the firewall/nsg in azure was changed.

0 Karma

jsalsbur
Explorer

Are you still having an issue with this stopping? Did you find a resolution? I ask because I seem to be having the same issue.

0 Karma

jaxjohnny2000
Builder

here is out inputs.conf from /opt/splunk/etc/apps/splunk_ta_o365/local

[splunk_ta_o365_management_activity://management_activity_audit_azure_ad]
content_type = Audit.AzureActiveDirectory
index = cloud_azure
interval = 60
tenant_name = splunk_o365_tenant
start_by_shell = false
number_of_threads = 8

[splunk_ta_o365_management_activity://management_activity_audit_general_input]
content_type = Audit.General
index = cloud_azure
interval = 60
tenant_name = splunk_o365_tenant
start_by_shell = false
number_of_threads = 8

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...