All Apps and Add-ons

Microsoft Azure Add-on: issues with not consuming all of our user objects with the AAD user input

tobiasboone1
Explorer

We operate a rather large M$ Tenant and I am running into issues with this add on not consuming all of our user objects with the AAD user input.  It dies around 550,000 users; I am assuming due to the bearer token coming from the graph API timing out at the 1 hour mark; all of the ingestion appears to start and stop at the 1 hour mark.

Anyone have any ideas how to get around this?  I really want to use splunk to version control and audit my user configurations offline and leverage this data for lookups coming from the azure related logs.  I can't however unless I get all of the user objects.

Second, I would love to see group memberships supported in this add on!!  This would be super helpful to target reports and audits against accounts.


Labels (2)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...