All Apps and Add-ons

Have I found.a bug? O365 TA reports incorrectly action

_joe
Communicator

Hello All,

I've noticed what I believe to be a bug between the splunk_ta_o365. I wanted to point it out or see if I am missing something here.

I have many events in office o365 which looks similar to this (It is confusing, but this user did NOT login):

Raw Logs:
Workload=AzureActiveDirectory
Operation=UserLoggedIn
ResultStatus=Succeeded
LogonError=UserAccountNotFound

The "Splunk Add-on for Microsoft Office 365" the following lookup: "splunk_ta_o365_cim_authentication.csv"
which compares the Workload, Operation, and ResultStatus fields - it does not consider LogonError. It OUTPUTs the following new fields:

dataset_name=authentication
action=success

The splunk_ta_o365 includes:
tag=authentication for "dataset_name=authentication"

Now the Authentication.Successful_Authentication (looks for tag=authentication action="success") data model incorrectly tells you a user has logged in when in fact, they failed because there was "UserAccountNotFound"

Using Splunk 8+, Splunk_SA_CIM 4.15.0, splunk_ta_o365 2.0.1

Labels (1)

arowsell_splunk
Splunk Employee
Splunk Employee

This issue has been addressed in the below bug:

ADDON-49247 - O365 CIM tagging not complete

Behaviour is addressed as below:
 
- Check if its Auth event or not
- If its auth event then we will check for the LogonError event field
- If we there is a Logon Error then action will be failure otherwise it will be Success
 
This fix should be included in the Splunk Add-on for Microsoft Office 365, 3.1.0 release which is targeted for End of April, 2022.
0 Karma

vanditanand
Splunk Employee
Splunk Employee

Hi @_joe , wanted to ask if you ever found a solution for this or were you able to find these successful or failed logins that Splunk reported in your O365 portal?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...