Stream Microsoft Entra logs to an event hub - Microsoft Entra ID (2024)

  • Article

Your Microsoft Entra tenant produces large amounts of data every second. Sign-in activity and logs of changes made in your tenant add up to a lot of data that can be hard to analyze. Integrating with Security Information and Event Management (SIEM) tools can help you gain insights into your environment.

This article shows how you can stream your logs to an event hub, to integrate with one of several SIEM tools.

Prerequisites

  • To stream logs to a SIEM tool, you first need to create an Azure event hub. Learn how to create an event hub.

  • Once you have an event hub that contains Microsoft Entra activity logs, you can set up the SIEM tool integration using the Microsoft Entra diagnostic settings.

Stream logs to an event hub

  1. Sign in to the Microsoft Entra admin center as at least a Security Administrator.

  2. Browse to Identity > Monitoring & health > Diagnostic settings. You can also select Export Settings from either the Audit Logs or Sign-ins page.

  3. Select + Add diagnostic setting to create a new integration or select Edit setting for an existing integration.

  4. Enter a Diagnostic setting name. If you're editing an existing integration, you can't change the name.

  5. Select the log categories that you want to stream.

  1. Select the Stream to an event hub check box.

  2. Select the Azure subscription, Event Hubs namespace, and optional event hub where you want to route the logs.

The subscription and Event Hubs namespace must both be associated with the Microsoft Entra tenant from where you're streaming the logs.

Once you have the Azure event hub ready, navigate to the SIEM tool you want to integrate with the activity logs. You'll finish the process in the SIEM tool.

We currently support Splunk, SumoLogic, and ArcSight. Select a tab to get started. Refer to the tool's documentation.

  • Splunk
  • SumoLogic
  • ArcSight

To use this feature, you need the Splunk Add-on for Microsoft Cloud Services.

Integrate Microsoft Entra logs with Splunk

  1. Open your Splunk instance and select Data Summary.

    Stream Microsoft Entra logs to an event hub - Microsoft Entra ID (1)

  2. Select the Sourcetypes tab, and then select mscs:azure:eventhub

    Stream Microsoft Entra logs to an event hub - Microsoft Entra ID (2)

Append body.records.category=AuditLogs to the search. The Microsoft Entra activity logs are shown in the following figure:

Stream Microsoft Entra logs to an event hub - Microsoft Entra ID (3)

If you can't install an add-on in your Splunk instance (for example, if you're using a proxy or running on Splunk Cloud), you can forward these events to the Splunk HTTP Event Collector. To do so, use this Azure function, which is triggered by new messages in the event hub.

Activity log integration options and considerations

If your current SIEM isn't supported in Azure Monitor diagnostics yet, you can set up custom tooling by using the Event Hubs API. To learn more, see the Getting started receiving messages from an event hub.

IBM QRadar is another option for integrating with Microsoft Entra activity logs. The DSM and Azure Event Hubs Protocol are available for download at IBM support. For more information about integration with Azure, go to the IBM QRadar Security Intelligence Platform 7.3.0 site.

Some sign-in categories contain large amounts of log data, depending on your tenant’s configuration. In general, the non-interactive user sign-ins and service principal sign-ins can be 5 to 10 times larger than the interactive user sign-ins.

Next steps

Stream Microsoft Entra logs to an event hub - Microsoft Entra ID (2024)
Top Articles
How to Unlock/Remove Google Find My Device 2024
Digital Wallet vs. Mobile Banking: What’s the Difference? | uLink
Use Copilot in Microsoft Teams meetings
Craigslist Home Health Care Jobs
Katie Pavlich Bikini Photos
Martha's Vineyard Ferry Schedules 2024
Tyrunt
Craigslist - Pets for Sale or Adoption in Zeeland, MI
Category: Star Wars: Galaxy of Heroes | EA Forums
Citi Card Thomas Rhett Presale
Maxpreps Field Hockey
3656 Curlew St
Knaben Pirate Download
Cvs Learnet Modules
California Department of Public Health
U/Apprenhensive_You8924
Huge Boobs Images
Https://Store-Kronos.kohls.com/Wfc
Vanessawest.tripod.com Bundy
Gayla Glenn Harris County Texas Update
Atlases, Cartography, Asia (Collection Dr. Dupuis), Arch…
European city that's best to visit from the UK by train has amazing beer
Wisconsin Volleyball Team Boobs Uncensored
Danielle Ranslow Obituary
The Creator Showtimes Near R/C Gateway Theater 8
15 Primewire Alternatives for Viewing Free Streams (2024)
Drying Cloths At A Hammam Crossword Clue
Pawn Shop Moline Il
Marquette Gas Prices
Democrat And Chronicle Obituaries For This Week
Generator Supercenter Heartland
Bursar.okstate.edu
R/Orangetheory
Bursar.okstate.edu
Http://N14.Ultipro.com
Craigslist Org Sf
Cvb Location Code Lookup
Mistress Elizabeth Nyc
Telegram update adds quote formatting and new linking options
Bianca Belair: Age, Husband, Height & More To Know
How Many Dogs Can You Have in Idaho | GetJerry.com
Umiami Sorority Rankings
Author's Purpose And Viewpoint In The Dark Game Part 3
How to Print Tables in R with Examples Using table()
Alpha Labs Male Enhancement – Complete Reviews And Guide
Beds From Rent-A-Center
News & Events | Pi Recordings
Take Me To The Closest Ups
Marine Forecast Sandy Hook To Manasquan Inlet
Assignation en paiement ou injonction de payer ?
Sml Wikia
Uncle Pete's Wheeling Wv Menu
Latest Posts
Article information

Author: Ray Christiansen

Last Updated:

Views: 5752

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Ray Christiansen

Birthday: 1998-05-04

Address: Apt. 814 34339 Sauer Islands, Hirtheville, GA 02446-8771

Phone: +337636892828

Job: Lead Hospitality Designer

Hobby: Urban exploration, Tai chi, Lockpicking, Fashion, Gunsmithing, Pottery, Geocaching

Introduction: My name is Ray Christiansen, I am a fair, good, cute, gentle, vast, glamorous, excited person who loves writing and wants to share my knowledge and understanding with you.