All Apps and Add-ons

Risky Signin and Risky user from Azure Identity protection to Splunk

penieldaniel
Explorer

I would like to ingest "Risky Sign-in" and "Risky User" events from Azure Entra Identity Protection into Splunk.

I have tried the following options but was unsuccessful:

  1. Splunk Add-on for Microsoft Azure – This add-on is no longer maintained or supported by Splunk.

  2. Azure Function App to Splunk HEC – Although this approach seems simpler and more cost-effective, I encountered several challenges during implementation.

I’m still open to using the second option since it involves minimal cost, but it would be helpful if there is a standard or recommended procedure available for this integration.

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@penieldaniel - I think you can still use this Add-on - https://splunkbase.splunk.com/app/3757

* This Add-on is not supported means, this is not part of Splunk support, but you can still use the Add-on.

 

Input

Microsoft Entra ID Risk Detection

Microsoft Graph

Permissions

(Application) IdentityRiskEvent.Read.All - Read all identity risk event information
(Application) IdentityRiskyUser.Read.All - Read all identity risk user information

N/A

Sourcetypes

azure:aad:identity_protection:risk_detection
azure:aad:identity_protection:risky_user

 

 

 

 

I hope this helps!!! Kindly upvote if it does!!!

View solution in original post

shashankD
Explorer

You can also use the add-on Splunk Add-on for Microsoft Cloud Services

0 Karma

penieldaniel
Explorer

Thanks, i tried this but I could not find "Microsoft Graph" as input if i use this Add-on. how can i send the pull request to the graph API ?
which other input can i use, please

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@penieldaniel - I think you can still use this Add-on - https://splunkbase.splunk.com/app/3757

* This Add-on is not supported means, this is not part of Splunk support, but you can still use the Add-on.

 

Input

Microsoft Entra ID Risk Detection

Microsoft Graph

Permissions

(Application) IdentityRiskEvent.Read.All - Read all identity risk event information
(Application) IdentityRiskyUser.Read.All - Read all identity risk user information

N/A

Sourcetypes

azure:aad:identity_protection:risk_detection
azure:aad:identity_protection:risky_user

 

 

 

 

I hope this helps!!! Kindly upvote if it does!!!

penieldaniel
Explorer

Hi @VatsalJagani 

Thanks for your reply.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...