All Apps and Add-ons
Highlighted

Microsoft Azure (in Government cloud) Active Directory Activity Logs (Audit and Sign-in) to Splunk

New Member

Hello everyone,

What are my options to retrieve Azure AD activity logs (audit & sign-in)? Azure environment is in MS government cloud.

I looked at two add-ons.
1. Splunk add-on for Microsoft Cloud services (v.3.1.0) - it has option for subscription audit log, but not AD activity logs.
2. Microsoft Azure Active Directory Reporting add-on (v1.1.0) - does not appear to support Azure AD in government cloud.

I think only other option that we could think of is to stream the logs to Event Hub and then integrate with Azure Monitor.

Are there any other options?

Thank you.

0 Karma