mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
181 lines
8.9 KiB
YAML
181 lines
8.9 KiB
YAML
name: Azure Active Directory
|
|
id: 7c12d2b2-2679-4806-b258-c17eaffbc66d
|
|
author: Patrick Bareiss, Splunk
|
|
source: Azure AD
|
|
sourcetype: azure:monitor:aad
|
|
separator: operationName
|
|
supported_TA:
|
|
name: Splunk Add-on for Microsoft Cloud Services
|
|
version: 5.2.2
|
|
url: https://splunkbase.splunk.com/app/3110
|
|
event_names:
|
|
- event_name: Azure Active Directory
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory.yml
|
|
- event_name: Azure Active Directory Add app role assignment to service principal
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_app_role_assignment_to_service_principal.yml
|
|
- event_name: Azure Active Directory Add member to role
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_member_to_role.yml
|
|
- event_name: Azure Active Directory Add owner to application
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_owner_to_application.yml
|
|
- event_name: Azure Active Directory Add service principal
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_service_principal.yml
|
|
- event_name: Azure Active Directory Add unverified domain
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_unverified_domain.yml
|
|
- event_name: Azure Active Directory Consent to application
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Consent_to_application.yml
|
|
- event_name: Azure Active Directory Disable Strong Authentication
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Disable_Strong_Authentication.yml
|
|
- event_name: Azure Active Directory Enable account
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Enable_account.yml
|
|
- event_name: Azure Active Directory Invite external user
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Invite_external_user.yml
|
|
- event_name: Azure Active Directory Reset password (by admin)
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Reset_password_(by_admin).yml
|
|
- event_name: Azure Active Directory Set domain authentication
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Set_domain_authentication.yml
|
|
- event_name: Azure Active Directory Sign-in activity
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Sign-in_activity.yml
|
|
- event_name: Azure Active Directory Update application
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_application.yml
|
|
- event_name: Azure Active Directory Update authorization policy
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_authorization_policy.yml
|
|
- event_name: Azure Active Directory Update user
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_user.yml
|
|
- event_name: Azure Active Directory User registered security info
|
|
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_User_registered_security_info.yml
|
|
fields:
|
|
- _time
|
|
- Level
|
|
- callerIpAddress
|
|
- category
|
|
- correlationId
|
|
- date_hour
|
|
- date_mday
|
|
- date_minute
|
|
- date_month
|
|
- date_second
|
|
- date_wday
|
|
- date_year
|
|
- date_zone
|
|
- durationMs
|
|
- host
|
|
- identity
|
|
- index
|
|
- linecount
|
|
- location
|
|
- operationName
|
|
- operationVersion
|
|
- properties.alternateSignInName
|
|
- properties.appDisplayName
|
|
- properties.appId
|
|
- properties.appServicePrincipalId
|
|
- properties.authenticationDetails{}.RequestSequence
|
|
- properties.authenticationDetails{}.StatusSequence
|
|
- properties.authenticationDetails{}.authenticationMethod
|
|
- properties.authenticationDetails{}.authenticationMethodDetail
|
|
- properties.authenticationDetails{}.authenticationStepDateTime
|
|
- properties.authenticationDetails{}.authenticationStepRequirement
|
|
- properties.authenticationDetails{}.authenticationStepResultDetail
|
|
- properties.authenticationDetails{}.succeeded
|
|
- properties.authenticationProcessingDetails{}.key
|
|
- properties.authenticationProcessingDetails{}.value
|
|
- properties.authenticationProtocol
|
|
- properties.authenticationRequirement
|
|
- properties.autonomousSystemNumber
|
|
- properties.clientAppUsed
|
|
- properties.clientCredentialType
|
|
- properties.conditionalAccessStatus
|
|
- properties.correlationId
|
|
- properties.createdDateTime
|
|
- properties.crossTenantAccessType
|
|
- properties.deviceDetail.deviceId
|
|
- properties.deviceDetail.operatingSystem
|
|
- properties.flaggedForReview
|
|
- properties.homeTenantId
|
|
- properties.id
|
|
- properties.incomingTokenType
|
|
- properties.ipAddress
|
|
- properties.isInteractive
|
|
- properties.isTenantRestricted
|
|
- properties.location.city
|
|
- properties.location.countryOrRegion
|
|
- properties.location.geoCoordinates.latitude
|
|
- properties.location.geoCoordinates.longitude
|
|
- properties.location.state
|
|
- properties.originalRequestId
|
|
- properties.processingTimeInMilliseconds
|
|
- properties.resourceDisplayName
|
|
- properties.resourceId
|
|
- properties.resourceServicePrincipalId
|
|
- properties.resourceTenantId
|
|
- properties.riskDetail
|
|
- properties.riskLevelAggregated
|
|
- properties.riskLevelDuringSignIn
|
|
- properties.riskState
|
|
- properties.rngcStatus
|
|
- properties.servicePrincipalId
|
|
- properties.signInIdentifier
|
|
- properties.ssoExtensionVersion
|
|
- properties.status.errorCode
|
|
- properties.status.failureReason
|
|
- properties.tokenIssuerName
|
|
- properties.tokenIssuerType
|
|
- properties.uniqueTokenIdentifier
|
|
- properties.userAgent
|
|
- properties.userDisplayName
|
|
- properties.userId
|
|
- properties.userPrincipalName
|
|
- properties.userType
|
|
- punct
|
|
- resourceId
|
|
- resultDescription
|
|
- resultSignature
|
|
- resultType
|
|
- source
|
|
- sourcetype
|
|
- splunk_server
|
|
- tenantId
|
|
- time
|
|
- timeendpos
|
|
- timestartpos
|
|
example_log: '{"time": "2023-01-23T21:29:14.1490728Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
|
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
|
|
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultType": "50126", "resultSignature":
|
|
"None", "resultDescription": "Invalid username or password or Invalid on-premise
|
|
username or password.", "durationMs": 0, "callerIpAddress": "35.80.10.10", "correlationId":
|
|
"1634ad3a-1f98-4964-add5-92fc58621944", "identity": "User30", "Level": 4, "location":
|
|
"US", "properties": {"id": "13148568-d61e-45eb-b38b-1fa63c106d00", "createdDateTime":
|
|
"2023-01-23T21:29:14.1490728+00:00", "userDisplayName": "User30", "userPrincipalName":
|
|
"user30@splunkresearch.com", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "appId":
|
|
"1b730954-1685-4b74-9bfd-dac224a7b894", "appDisplayName": "Azure Active Directory
|
|
PowerShell", "ipAddress": "35.80.10.10", "status": {"errorCode": 50126, "failureReason":
|
|
"Invalid username or password or Invalid on-premise username or password."}, "clientAppUsed":
|
|
"Mobile Apps and Desktop clients", "userAgent": "Mozilla/5.0 (Windows NT; Windows
|
|
NT 10.0; en-US) WindowsPowerShell/5.1.14393.5127", "deviceDetail": {"deviceId":
|
|
"", "operatingSystem": "Windows 10"}, "location": {"city": "Boardman", "state":
|
|
"Oregon", "countryOrRegion": "US", "geoCoordinates": {"latitude": 45.83599853515625,
|
|
"longitude": -119.6989974975586}}, "correlationId": "1634ad3a-1f98-4964-add5-92fc58621944",
|
|
"conditionalAccessStatus": "notApplied", "appliedConditionalAccessPolicies": [],
|
|
"authenticationContextClassReferences": [], "originalRequestId": "13148568-d61e-45eb-b38b-1fa63c106d00",
|
|
"isInteractive": true, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
|
|
[{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Is CAE Token",
|
|
"value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none",
|
|
"processingTimeInMilliseconds": 47, "riskDetail": "none", "riskLevelAggregated":
|
|
"none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes":
|
|
[], "riskEventTypes_v2": [], "resourceDisplayName": "Windows Azure Active Directory",
|
|
"resourceId": "00000002-0000-0000-c000-000000000000", "resourceTenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e",
|
|
"homeTenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "authenticationDetails":
|
|
[{"authenticationStepDateTime": "2023-01-23T21:29:14.1490728+00:00", "authenticationMethod":
|
|
"Password", "authenticationMethodDetail": "Password in the cloud", "succeeded":
|
|
false, "authenticationStepResultDetail": "Invalid username or password or Invalid
|
|
on-premise username or password.", "authenticationStepRequirement": "Primary authentication",
|
|
"StatusSequence": 0, "RequestSequence": 1}], "authenticationRequirementPolicies":
|
|
[], "authenticationRequirement": "singleFactorAuthentication", "alternateSignInName":
|
|
"user30@splunkresearch.com", "signInIdentifier": "user30@splunkresearch.com", "servicePrincipalId":
|
|
"", "userType": "Member", "flaggedForReview": false, "isTenantRestricted": false,
|
|
"autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails":
|
|
{}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "aIUUEx7W60Wzix-mPBBtAA",
|
|
"authenticationStrengths": [], "incomingTokenType": "none", "authenticationProtocol":
|
|
"none", "appServicePrincipalId": null, "resourceServicePrincipalId": "4d6bd7de-c9bc-45cc-b8ec-ae315f66bf77",
|
|
"rngcStatus": 0}}'
|