All Apps and Add-ons

How do I get Entra logs (formerly Active directory), into Splunk Cloud?

MelV
New Member

The goal is to get Entra logs into Splunk Cloud and alert on non-domain affiliated logins. Can't seem to find any documentation on.

Labels (1)
0 Karma

marnall
Motivator

You probably want the Splunk Add on for Microsoft Azure (https://splunkbase.splunk.com/app/3757)

There are set-up instructions described at https://github.com/splunk/splunk-add-on-microsoft-azure/wiki (see the sections on Configuration) on the right.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...