Plan an Azure AD reporting and monitoring deployment

cruise 331 Reputation points
2021-04-02T02:31:04.637+00:00

Integration in SIEM systems SIEM integration. ‎The need to integrate and stream Azure AD sign in logs and audit logs to existing SIEM systems. How to do?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,831 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,686 questions
0 comments No comments
{count} votes

Accepted answer
  1. SUNOJ KUMAR YELURU 13,951 Reputation points MVP
    2021-04-02T06:54:52.557+00:00

    HI @cruise

    You can route Azure Active Directory (Azure AD) activity logs to several endpoints for long term retention and data insights. This feature allows you to:

    Archive Azure AD activity logs to an Azure storage account, to retain the data for a long time.
    Stream Azure AD activity logs to an Azure event hub for analytics, using popular Security Information and Event Management (SIEM) tools, such as Splunk and QRadar.
    Integrate Azure AD activity logs with your own custom log solutions by streaming them to an event hub.
    Send Azure AD activity logs to Azure Monitor logs to enable rich visualizations, monitoring and alerting on the connected data.
    Refer below URL's process steps.
    https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-activity-logs-azure-monitor
    Plan an Azure Active Directory reporting and monitoring deployment

    If the Answer is helpful, please click Accept Answer and up-vote, this can be beneficial to other community members.


0 additional answers

Sort by: Most helpful