@@ -10,7 +10,7 @@ separator: operationName
10
10
supported_TA :
11
11
- name : Splunk Add-on for Microsoft Cloud Services
12
12
url : https://splunkbase.splunk.com/app/3110
13
- version : 5.4.2
13
+ version : 5.4.3
14
14
fields :
15
15
- action
16
16
- additional_details
@@ -133,5 +133,40 @@ fields:
133
133
- _sourcetype
134
134
- _subsecond
135
135
- _time
136
- example_log : |-
137
- {"time": "2023-01-12T19:22:14.5285742Z", "resourceId": "/tenants/95d19bda-09de-4d93-b7ae-acecd1e68186/providers/Microsoft.aadiam", "operationName": "Sign-in activity", "operationVersion": "1.0", "category": "NonInteractiveUserSignInLogs", "tenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "resultType": "0", "resultSignature": "None", "durationMs": 0, "callerIpAddress": "34.1.3.194", "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65", "identity": "User30", "Level": 4, "location": "US", "properties": {"id": "0f94f5fb-3583-4c46-9bfa-0390c1988800", "createdDateTime": "2023-01-12T19:22:14.5285742+00:00", "userDisplayName": "User30", "userPrincipalName": "[email protected] ", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "appId": "4765445b-32c6-49b0-83e6-1d93765276ca", "appDisplayName": "OfficeHome", "ipAddress": "34.1.3.194", "status": {"errorCode": 0, "additionalDetails": "MFA requirement satisfied by claim in the token"}, "clientAppUsed": "Browser", "deviceDetail": {"deviceId": "", "operatingSystem": "Windows", "browser": "Rich Client 4.43.0.0"}, "location": {"city": "Boardman", "state": "Oregon", "countryOrRegion": "US", "geoCoordinates": {"latitude": 45.73722839355469, "longitude": -119.81143188476562}}, "mfaDetail": {}, "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65", "conditionalAccessStatus": "notApplied", "appliedConditionalAccessPolicies": [{"id": "SecurityDefaults", "displayName": "Security Defaults", "enforcedGrantControls": [], "enforcedSessionControls": [], "result": "success", "conditionsSatisfied": 3, "conditionsNotSatisfied": 0}], "authenticationContextClassReferences": [], "originalRequestId": "0f94f5fb-3583-4c46-9bfa-0390c1988800", "isInteractive": false, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails": [{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Oauth Scope Info", "value": "[\"OfficeHome.All\"]"}, {"key": "Is CAE Token", "value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none", "processingTimeInMilliseconds": 192, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName": "OfficeHome", "resourceId": "4765445b-32c6-49b0-83e6-1d93765276ca", "resourceTenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "homeTenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "authenticationDetails": [{"authenticationStepDateTime": "2023-01-12T19:22:14.5285742+00:00", "authenticationMethod": "Previously satisfied", "succeeded": true, "authenticationStepResultDetail": "MFA requirement satisfied by claim in the token", "authenticationStepRequirement": "Primary authentication"}], "authenticationRequirementPolicies": [{"requirementProvider": "user", "detail": "Per-user MFA"}], "authenticationRequirement": "multiFactorAuthentication", "servicePrincipalId": "", "userType": "Member", "flaggedForReview": false, "isTenantRestricted": false, "autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails": {}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "-_WUD4M1Rkyb-gOQwZiIAA", "authenticationStrengths": [], "incomingTokenType": "primaryRefreshToken", "authenticationProtocol": "none", "appServicePrincipalId": null, "resourceServicePrincipalId": null, "rngcStatus": 0}}
136
+ example_log : ' {"time": "2023-01-12T19:22:14.5285742Z", "resourceId": "/tenants/95d19bda-09de-4d93-b7ae-acecd1e68186/providers/Microsoft.aadiam",
137
+ "operationName": "Sign-in activity", "operationVersion": "1.0", "category": "NonInteractiveUserSignInLogs",
138
+ "tenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "resultType": "0", "resultSignature":
139
+ "None", "durationMs": 0, "callerIpAddress": "34.1.3.194", "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65",
140
+ "identity": "User30", "Level": 4, "location": "US", "properties": {"id": "0f94f5fb-3583-4c46-9bfa-0390c1988800",
141
+ "createdDateTime": "2023-01-12T19:22:14.5285742+00:00", "userDisplayName": "User30",
142
+ "userPrincipalName": "[email protected] ", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998",
143
+ "appId": "4765445b-32c6-49b0-83e6-1d93765276ca", "appDisplayName": "OfficeHome",
144
+ "ipAddress": "34.1.3.194", "status": {"errorCode": 0, "additionalDetails": "MFA
145
+ requirement satisfied by claim in the token"}, "clientAppUsed": "Browser", "deviceDetail":
146
+ {"deviceId": "", "operatingSystem": "Windows", "browser": "Rich Client 4.43.0.0"},
147
+ "location": {"city": "Boardman", "state": "Oregon", "countryOrRegion": "US", "geoCoordinates":
148
+ {"latitude": 45.73722839355469, "longitude": -119.81143188476562}}, "mfaDetail":
149
+ {}, "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65", "conditionalAccessStatus":
150
+ "notApplied", "appliedConditionalAccessPolicies": [{"id": "SecurityDefaults", "displayName":
151
+ "Security Defaults", "enforcedGrantControls": [], "enforcedSessionControls": [],
152
+ "result": "success", "conditionsSatisfied": 3, "conditionsNotSatisfied": 0}], "authenticationContextClassReferences":
153
+ [], "originalRequestId": "0f94f5fb-3583-4c46-9bfa-0390c1988800", "isInteractive":
154
+ false, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
155
+ [{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Oauth Scope
156
+ Info", "value": "[\"OfficeHome.All\"]"}, {"key": "Is CAE Token", "value": "False"}],
157
+ "networkLocationDetails": [], "clientCredentialType": "none", "processingTimeInMilliseconds":
158
+ 192, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn":
159
+ "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName":
160
+ "OfficeHome", "resourceId": "4765445b-32c6-49b0-83e6-1d93765276ca", "resourceTenantId":
161
+ "95d19bda-09de-4d93-b7ae-acecd1e68186", "homeTenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186",
162
+ "authenticationDetails": [{"authenticationStepDateTime": "2023-01-12T19:22:14.5285742+00:00",
163
+ "authenticationMethod": "Previously satisfied", "succeeded": true, "authenticationStepResultDetail":
164
+ "MFA requirement satisfied by claim in the token", "authenticationStepRequirement":
165
+ "Primary authentication"}], "authenticationRequirementPolicies": [{"requirementProvider":
166
+ "user", "detail": "Per-user MFA"}], "authenticationRequirement": "multiFactorAuthentication",
167
+ "servicePrincipalId": "", "userType": "Member", "flaggedForReview": false, "isTenantRestricted":
168
+ false, "autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails":
169
+ {}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "-_WUD4M1Rkyb-gOQwZiIAA",
170
+ "authenticationStrengths": [], "incomingTokenType": "primaryRefreshToken", "authenticationProtocol":
171
+ "none", "appServicePrincipalId": null, "resourceServicePrincipalId": null, "rngcStatus":
172
+ 0}}'
0 commit comments