Hi -
We have the Splunk Add-on for Microsoft Cloud Services installed and are currently collecting Azure "Activity Logs" into Splunk.
However, we'd also like to capture the Azure (portal.azure.com) -> Azure Active Directory -> "Sign-Ins" data into Splunk.
Can anyone advise as how to achieve this?
Many thanks,
Tom
do it via API: https://docs.microsoft.com/en-us/azure/active-directory/active-directory-reporting-guide all signin data should be pulled
I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.
All authentication can be ingested using the O365 Management Activity input. You just need to select the Azure Authentication from that input. This is technically ingesting all Azure authentication beyong O365 apps.
You can use the Azure audit input for Azure portal audit related.
Thanks ehaddad - when I attempt to link our Office365 account I get the following error when signing in:
"Sorry, but we're having trouble signing you in. We received a bad request"
and
"Resource 'https://manage.office.com' is disabled"
Any further ideas on this?
I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.
What errors are you getting in index=_internal?
I would suggest to file a support ticket and upload diag on that ticket for us to get a closer look. Hard to tell what the problem is without the log files.
Copied the logs for a short period. Can this help?
12/15/16
3:31:54.878 PM
12-15-2016 15:31:54.878 +0000 WARN FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host = prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.941 PM
12-15-2016 15:31:19.941 +0000 WARN SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host = prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.888 PM
12-15-2016 15:31:19.888 +0000 WARN SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host = prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.833 PM
12-15-2016 15:31:19.833 +0000 WARN FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host = prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.341 PM
12-15-2016 15:31:02.341 +0000 WARN SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host = prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.227 PM
12-15-2016 15:31:02.227 +0000 WARN SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host = prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.103 PM
12-15-2016 15:31:02.103 +0000 WARN FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'