Post upgrading Microsoft Azure Add on for Splunk to 3.2.0 we are not receiving authentication details in Splunk. Also, non-interactive login details are not available.
Field to check if the authentication is success or failed is not in the raw logs, field name - authenticationDetailssucceeded. Other authentication details are also missing.
This was resolved by changing endpoint as beta instead of v1.0 in Inputs.
I'm not an Azure expert, but I always use Office 365 Add-on to get login details from Azure.
please use this addon to onboard the splunk azure data
https://splunkbase.splunk.com/app/3110/
this is the official azure add on.
Best Regards
Alessandro