Azure Active Directory reporting ,How to retain and import to third party for long term?

cruise 331 Reputation points
2021-04-02T02:19:53.487+00:00

Azure AD monitoring enables you to route your logs generated by Azure AD reporting to different target systems. You can then either retain it for long-term use or integrate it with third-party Security Information and Event Management (SIEM) tools to gain insights into your environment.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2021-04-06T20:58:30.247+00:00

    Hi @cruise ,

    In that case you can archive and query the logs, send the logs to Azure Event Hub, and send them from Event Hub to your third party SIEM tool. The documentation contains a decision flow chart for this exact scenario:

    84987-image.png


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.