All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services: Can Azure AD Identity Protection Risk events be ingested?

jwalzerpitt
Motivator

Does the Splunk Add-on for Microsoft Cloud Services support ingesting Azure AD Identity Protection Risk events?

Thx

0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

The Splunk Add-on for Microsoft Cloud Services does not currently integrate with the Azure AD Identity Protection graph API (https://docs.microsoft.com/en-us/azure/active-directory/active-directory-identityprotection-graph-ge... ) You can use the Splunk Add-on builder to interface with this API to pull these events though.

View solution in original post

jconger
Splunk Employee
Splunk Employee

The Splunk Add-on for Microsoft Cloud Services does not currently integrate with the Azure AD Identity Protection graph API (https://docs.microsoft.com/en-us/azure/active-directory/active-directory-identityprotection-graph-ge... ) You can use the Splunk Add-on builder to interface with this API to pull these events though.

View solution in original post

jwalzerpitt
Motivator

Thx for the reply and information

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!