Alerting

DUO Alerts

nathant27
Engager

What are a few basic alerts i can run to test if my configuration is working? I created two but have not received any alerts.

Tags (1)
0 Karma

nathant27
Engager

No worries, I do appreciate you taking your time out to assist me!

0 Karma

nathant27
Engager

Hi Jodyfsu!

I am using duo for MFA as well and moving toward using it for SSO. I would like to get alerts whenever a user is created in duo and when a user authenticates from a location that's not in the city our office is located.

0 Karma

jodyfsu
Path Finder

Excellent. My guess is you may be able to use your SSO application logs (cas, shib, etc) to get IP and USERID as well as other info. As for the User being created in DUO, unless you have the DUO logs being pumped into Splunk you may not be able to see that. Depending on your process for adding users into DUO you may be able to get the info in another way. When we rolled DUO out for our Students we used the DUO API and created an intercept for Users not already in DUO. The User would SSO auth, then the app would use the API to check DUO to see if the User was in DUO. If not, they would then be given the option to create their account. We would then push the data from our system to DUO and would use the success from that to count the users added to DUO.

Hope this helps.

0 Karma

nathant27
Engager

I believe that DUO logs are being pumped to Splunk. I setup a connector and I can see data on the dashboard. I also set up an alert and a trigger action but it doesn't seem to work. I am probably doing something wrong.

0 Karma

jodyfsu
Path Finder

I used to be our DUO Admin but have moved on. In the DUO Telephony log you should be able to look for Enrollment to key on users being added.

We are not getting the DUO logs into Splunk so I can't really provide more than ideas 🙂

0 Karma

jodyfsu
Path Finder

Hey nathant27, what is it you are using DUO for? I am using DUO for Peoplesoft MFA and look to the values in my PS logs for the DUO hits. Depending on what application you are using DUO for you may be able to look to those logs.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...