All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

djukicm
Explorer

Hi -

We have the Splunk Add-on for Microsoft Cloud Services installed and are currently collecting Azure "Activity Logs" into Splunk.

However, we'd also like to capture the Azure (portal.azure.com) -> Azure Active Directory -> "Sign-Ins" data into Splunk.

Can anyone advise as how to achieve this?

Many thanks,
Tom

dstefan
New Member
0 Karma

arunkabrahamdnb
New Member

I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

All authentication can be ingested using the O365 Management Activity input. You just need to select the Azure Authentication from that input. This is technically ingesting all Azure authentication beyong O365 apps.
You can use the Azure audit input for Azure portal audit related.

0 Karma

djukicm
Explorer

Thanks ehaddad - when I attempt to link our Office365 account I get the following error when signing in:

"Sorry, but we're having trouble signing you in. We received a bad request"

and

"Resource 'https://manage.office.com' is disabled"

Any further ideas on this?

0 Karma

arunkabrahamdnb
New Member

I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

What errors are you getting in index=_internal?
I would suggest to file a support ticket and upload diag on that ticket for us to get a closer look. Hard to tell what the problem is without the log files.

0 Karma

arunkabrahamdnb
New Member

Copied the logs for a short period. Can this help?

12/15/16
3:31:54.878 PM  
12-15-2016 15:31:54.878 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.941 PM  
12-15-2016 15:31:19.941 +0000 WARN  SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.888 PM  
12-15-2016 15:31:19.888 +0000 WARN  SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.833 PM  
12-15-2016 15:31:19.833 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.341 PM  
12-15-2016 15:31:02.341 +0000 WARN  SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.227 PM  
12-15-2016 15:31:02.227 +0000 WARN  SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.103 PM  
12-15-2016 15:31:02.103 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...