All Apps and Add-ons

Risky Signin and Risky user from Azure Identity protection to Splunk

penieldaniel
Explorer

I would like to ingest "Risky Sign-in" and "Risky User" events from Azure Entra Identity Protection into Splunk.

I have tried the following options but was unsuccessful:

  1. Splunk Add-on for Microsoft Azure – This add-on is no longer maintained or supported by Splunk.

  2. Azure Function App to Splunk HEC – Although this approach seems simpler and more cost-effective, I encountered several challenges during implementation.

I’m still open to using the second option since it involves minimal cost, but it would be helpful if there is a standard or recommended procedure available for this integration.

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@penieldaniel - I think you can still use this Add-on - https://splunkbase.splunk.com/app/3757

* This Add-on is not supported means, this is not part of Splunk support, but you can still use the Add-on.

 

Input

Microsoft Entra ID Risk Detection

Microsoft Graph

Permissions

(Application) IdentityRiskEvent.Read.All - Read all identity risk event information
(Application) IdentityRiskyUser.Read.All - Read all identity risk user information

N/A

Sourcetypes

azure:aad:identity_protection:risk_detection
azure:aad:identity_protection:risky_user

 

 

 

 

I hope this helps!!! Kindly upvote if it does!!!

View solution in original post

shashankD
Explorer

You can also use the add-on Splunk Add-on for Microsoft Cloud Services

0 Karma

penieldaniel
Explorer

Thanks, i tried this but I could not find "Microsoft Graph" as input if i use this Add-on. how can i send the pull request to the graph API ?
which other input can i use, please

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@penieldaniel - I think you can still use this Add-on - https://splunkbase.splunk.com/app/3757

* This Add-on is not supported means, this is not part of Splunk support, but you can still use the Add-on.

 

Input

Microsoft Entra ID Risk Detection

Microsoft Graph

Permissions

(Application) IdentityRiskEvent.Read.All - Read all identity risk event information
(Application) IdentityRiskyUser.Read.All - Read all identity risk user information

N/A

Sourcetypes

azure:aad:identity_protection:risk_detection
azure:aad:identity_protection:risky_user

 

 

 

 

I hope this helps!!! Kindly upvote if it does!!!

penieldaniel
Explorer

Hi @VatsalJagani 

Thanks for your reply.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...