Activity Directory Sign-In logs won't send to Event Hub

Matthew B 1 Reputation point
2021-11-05T13:32:03.433+00:00

Hi

I've selected the following events in Active Directory Sign-In logs to send to an event hub

AuditLogs

SignInLogs

In order to export Sign-in data, your organization needs Azure AD P1 or P2 license. If you don't have a P1 or P2, start a free trial.
NonInteractiveUserSignInLogs

ServicePrincipalSignInLogs

ManagedIdentitySignInLogs

ProvisioningLogs

ADFSSignInLogs

RiskyUsers

UserRiskEvents

The correct event hub and subscription are selected.

However when I go to the event hub with the same name, none of the events are displayed. Even with most filters removed.

How do we get the signin events into the event hub so we can ship them off to our SIEM?

Thanks,

Matthew

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,560 questions
{count} votes