Hi @cruise ,
In that case you can archive and query the logs, send the logs to Azure Event Hub, and send them from Event Hub to your third party SIEM tool. The documentation contains a decision flow chart for this exact scenario:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Azure AD monitoring enables you to route your logs generated by Azure AD reporting to different target systems. You can then either retain it for long-term use or integrate it with third-party Security Information and Event Management (SIEM) tools to gain insights into your environment.
Hi @cruise ,
In that case you can archive and query the logs, send the logs to Azure Event Hub, and send them from Event Hub to your third party SIEM tool. The documentation contains a decision flow chart for this exact scenario: