Security

Microsoft Azure Add on for Splunk NO authenticationDetail resource type

zschmerber
Explorer

It seems that the authenticationDetail resource type is no longer part of the: Sign-ins - Azure AD sign-ins including conditional access policies and MFA

After researching the issue it seems only the Beta API NOT the v1.0 API has the data we want. However toggling the addon to Beta Has not affect on the log structure we still don't see authenticationDetail resource type in the logs. 

Microsoft Azure Add-on for Splunk Version: 3.1.1
Splunk Enterprise 8.1

Is this a problem with the TA not having the correct python to pull the data or the MS API changing ? worked in April this year. 

0 Karma

zschmerber
Explorer

I was able to fix this by reinstalling the app.

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...