Getting Data In

Splunk and Microsoft Advanced Threat Analytics

alonsocaio
Contributor

Is there any way to integrate and send Microsoft Advanced Threat Analytics events to Splunk?

0 Karma
1 Solution

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

View solution in original post

25D55AD2
Engager

But are these logs well parsed by default by Splunk?

alonsocaio
Contributor

Yes, they are. I have created a custom sourcetype for MS ATA so I could extract more fields, but It is well parsed since It has field : value in its logs and also have some delimiters.

0 Karma

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

edhealea
Path Finder

Where you able to get this to work? I have added my syslog server into the ATA config under the syslog server setting but I am not getting any alerts. I can generate a test message and receive it in our syslog server.

alonsocaio
Contributor

I have configured Syslog Server Endpoint (server:port), Transport (UDP) and Format (RFC 5424), following the docs. Take a look at the Notifications menu and go to Syslog Notifications. Check if all options are enabled.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...