Getting Data In

Splunk and Microsoft Advanced Threat Analytics

alonsocaio
Contributor

Is there any way to integrate and send Microsoft Advanced Threat Analytics events to Splunk?

0 Karma
1 Solution

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

View solution in original post

25D55AD2
Engager

But are these logs well parsed by default by Splunk?

alonsocaio
Contributor

Yes, they are. I have created a custom sourcetype for MS ATA so I could extract more fields, but It is well parsed since It has field : value in its logs and also have some delimiters.

0 Karma

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

edhealea
Path Finder

Where you able to get this to work? I have added my syslog server into the ATA config under the syslog server setting but I am not getting any alerts. I can generate a test message and receive it in our syslog server.

alonsocaio
Contributor

I have configured Syslog Server Endpoint (server:port), Transport (UDP) and Format (RFC 5424), following the docs. Take a look at the Notifications menu and go to Syslog Notifications. Check if all options are enabled.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...