Splunk Enterprise Security

Adding an Azure sign in field to Splunk ES authentication data model

jwalzerpitt
Influencer

We recently started to ingest Microsoft's Azure sign-in events and one thing I've noticed are some values from the clientAppUsed field throws off the Geographically Improbable Access Detected alert.

I stopped the acceleration on the Authentication data model so I could go in and see if I could add the field clientAppUsed, but it's not coming up a field to be added (using the 'Add Auto-Extracted Field' option).

If I run a search on index=azuread the clientAppUsed field is parsed automatically, but it seems to not present itself within the Authentication data model.

How can I add the clientAppUsed field in the Authentication data model so I can then work to filter some values out to fix the false positives in the Geographically Improbable Access Detected alert?

Thx

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...