Trying to figure out which one i need to have visibility of Azure AD security Logs?
We use Splunk Add-on for Microsoft Office 365 and it is able to pull those logs. Just make sure you have an app registration setup with the correct permissions and the client key beforehand.
Pretty simply setup, just define your input then select what logs you want
View solution in original post