All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

djukicm
Explorer

Hi -

We have the Splunk Add-on for Microsoft Cloud Services installed and are currently collecting Azure "Activity Logs" into Splunk.

However, we'd also like to capture the Azure (portal.azure.com) -> Azure Active Directory -> "Sign-Ins" data into Splunk.

Can anyone advise as how to achieve this?

Many thanks,
Tom

dstefan
New Member
0 Karma

arunkabrahamdnb
New Member

I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

All authentication can be ingested using the O365 Management Activity input. You just need to select the Azure Authentication from that input. This is technically ingesting all Azure authentication beyong O365 apps.
You can use the Azure audit input for Azure portal audit related.

0 Karma

djukicm
Explorer

Thanks ehaddad - when I attempt to link our Office365 account I get the following error when signing in:

"Sorry, but we're having trouble signing you in. We received a bad request"

and

"Resource 'https://manage.office.com' is disabled"

Any further ideas on this?

0 Karma

arunkabrahamdnb
New Member

I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

What errors are you getting in index=_internal?
I would suggest to file a support ticket and upload diag on that ticket for us to get a closer look. Hard to tell what the problem is without the log files.

0 Karma

arunkabrahamdnb
New Member

Copied the logs for a short period. Can this help?

12/15/16
3:31:54.878 PM  
12-15-2016 15:31:54.878 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.941 PM  
12-15-2016 15:31:19.941 +0000 WARN  SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.888 PM  
12-15-2016 15:31:19.888 +0000 WARN  SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.833 PM  
12-15-2016 15:31:19.833 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.341 PM  
12-15-2016 15:31:02.341 +0000 WARN  SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.227 PM  
12-15-2016 15:31:02.227 +0000 WARN  SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.103 PM  
12-15-2016 15:31:02.103 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...