Microsoft 365 integration with 2.4? #12826
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU24 RAM192 Storage for /1 TB Storage for /nsm40 TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI'm looking for help on how to ingest logs from Microsoft 365 in Security Onion 2.4. I had it working with 2.3 by registering an Application in Azure (Entra), providing the required permissions to M365 resources and then adding the credentials to the filebeat docker container on my manager node. I have been unable to find information on how to make this work with Elastic Agent in 2.4. I should mention that I have other integrations that were previously working in 2.3 that I want to configure as well, such as Okta, Sophos and sFlow, but I'm not to that point yet. M365 is my primary concern at the moment. Any suggestions are welcomed and appreciated. Thanks. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Kinda off-topic, but I always find those 2 words in the same sentence cringeworthy - Microsoft and integration. It was always more of a Borg-type thing to me, ya know - assimilation. |
Beta Was this translation helpful? Give feedback.
-
All of those items should be supported via Elastic Integrations.
There's a video on our Youtube site for using the Elastic Integration for PFSense logs -- the methodology is similar, that might be worth watching for you. |
Beta Was this translation helpful? Give feedback.
All of those items should be supported via Elastic Integrations.
There's a video on our Youtube site for using the Elastic Integra…