Getting Data In

Splunk and Microsoft Advanced Threat Analytics

alonsocaio
Contributor

Is there any way to integrate and send Microsoft Advanced Threat Analytics events to Splunk?

0 Karma
1 Solution

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

View solution in original post

25D55AD2
Engager

But are these logs well parsed by default by Splunk?

alonsocaio
Contributor

Yes, they are. I have created a custom sourcetype for MS ATA so I could extract more fields, but It is well parsed since It has field : value in its logs and also have some delimiters.

0 Karma

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

edhealea
Path Finder

Where you able to get this to work? I have added my syslog server into the ATA config under the syslog server setting but I am not getting any alerts. I can generate a test message and receive it in our syslog server.

alonsocaio
Contributor

I have configured Syslog Server Endpoint (server:port), Transport (UDP) and Format (RFC 5424), following the docs. Take a look at the Notifications menu and go to Syslog Notifications. Check if all options are enabled.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...