I would like to ingest "Risky Sign-in" and "Risky User" events from Azure Entra Identity Protection into Splunk. I have tried the following options but was unsuccessful: Splunk Add-on for Microsoft Azure – This add-on is no longer maintained or supported by Splunk. Azure Function App to Splunk HEC – Although this approach seems simpler and more cost-effective, I encountered several challenges during implementation. I’m still open to using the second option since it involves minimal cost, but it would be helpful if there is a standard or recommended procedure available for this integration.
... View more