Getting Data In

Splunk and Microsoft Advanced Threat Analytics

alonsocaio
Contributor

Is there any way to integrate and send Microsoft Advanced Threat Analytics events to Splunk?

0 Karma
1 Solution

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

View solution in original post

25D55AD2
Engager

But are these logs well parsed by default by Splunk?

alonsocaio
Contributor

Yes, they are. I have created a custom sourcetype for MS ATA so I could extract more fields, but It is well parsed since It has field : value in its logs and also have some delimiters.

0 Karma

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

edhealea
Path Finder

Where you able to get this to work? I have added my syslog server into the ATA config under the syslog server setting but I am not getting any alerts. I can generate a test message and receive it in our syslog server.

alonsocaio
Contributor

I have configured Syslog Server Endpoint (server:port), Transport (UDP) and Format (RFC 5424), following the docs. Take a look at the Notifications menu and go to Syslog Notifications. Check if all options are enabled.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...