All Apps and Add-ons
Highlighted

Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

Explorer

Hi -

We have the Splunk Add-on for Microsoft Cloud Services installed and are currently collecting Azure "Activity Logs" into Splunk.

However, we'd also like to capture the Azure (portal.azure.com) -> Azure Active Directory -> "Sign-Ins" data into Splunk.

Can anyone advise as how to achieve this?

Many thanks,
Tom

Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

Contributor

All authentication can be ingested using the O365 Management Activity input. You just need to select the Azure Authentication from that input. This is technically ingesting all Azure authentication beyong O365 apps.
You can use the Azure audit input for Azure portal audit related.

0 Karma
Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

New Member

I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.

0 Karma
Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

Contributor

What errors are you getting in index=_internal?
I would suggest to file a support ticket and upload diag on that ticket for us to get a closer look. Hard to tell what the problem is without the log files.

0 Karma
Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

New Member

Copied the logs for a short period. Can this help?

12/15/16
3:31:54.878 PM  
12-15-2016 15:31:54.878 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.941 PM  
12-15-2016 15:31:19.941 +0000 WARN  SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.888 PM  
12-15-2016 15:31:19.888 +0000 WARN  SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:19.833 PM  
12-15-2016 15:31:19.833 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.341 PM  
12-15-2016 15:31:02.341 +0000 WARN  SearchOperator:kv - IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.227 PM  
12-15-2016 15:31:02.227 +0000 WARN  SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='mscs_counter_name'
host =  prd-p-59vhkzlq9h5s source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
12/15/16
3:31:02.103 PM  
12-15-2016 15:31:02.103 +0000 WARN  FieldAliaser - Invalid field alias specification in stanza 'ri:pas:application': FIELDALIAS-event_id='event_id AS event_id'
0 Karma
Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

Explorer

Thanks ehaddad - when I attempt to link our Office365 account I get the following error when signing in:

"Sorry, but we're having trouble signing you in. We received a bad request"

and

"Resource 'https://manage.office.com' is disabled"

Any further ideas on this?

0 Karma
Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

New Member

I am using this add-on and was able to get logs from table and blob storage to Splunk.
But even after configuring the AD application details and audit input, Activity logs are not getting indexed in Splunk.
I have the requirement of Active directory Audit and Sign in logs to be indexed. Can you please help me on this?
1) Indexing Azure activity logs
2) Indexing Azure AD audit and Sign in logs.

0 Karma
Highlighted

Re: Splunk Add-on for Microsoft Cloud Services: How to index Azure Active Directory "Sign-Ins" data?

New Member
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.