Getting Data In

Azure Sign In logs in Real Time

quantrium-anant
Engager

Hello

 

I am new to Splunk.

I wish to use the sign in information from Azure AD/Entra ID. Is there a way to get these logs (sign-in logs) in real-time? Or probably even the syslog for sign-in activity?

I have been through Microsoft Log Analytics Workspace, it suggests latency for the same to be 20 sec to 3 min. Is there a way to reduce this?

Is a documentation supporting confirming the latency limits?

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

have you try this https://splunkbase.splunk.com/app/3757 ?

Of course if the issue is that Azure has this internal delays there is nothing that could fixed by integrations. If this is the issue, then you should contact to Azure support and ask from them if there are any workarounds for it.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

have you try this https://splunkbase.splunk.com/app/3757 ?

Of course if the issue is that Azure has this internal delays there is nothing that could fixed by integrations. If this is the issue, then you should contact to Azure support and ask from them if there are any workarounds for it.

r. Ismo

quantrium-anant
Engager

Thank you @isoutamo for your reply.

I will look into the tool.

 

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...