@@ -10,7 +10,7 @@ separator: operationName
1010supported_TA :
1111- name : Splunk Add-on for Microsoft Cloud Services
1212 url : https://splunkbase.splunk.com/app/3110
13- version : 5.4.2
13+ version : 5.4.3
1414fields :
1515- action
1616- additional_details
@@ -133,5 +133,40 @@ fields:
133133- _sourcetype
134134- _subsecond
135135- _time
136- example_log : |-
137- {"time": "2023-01-12T19:22:14.5285742Z", "resourceId": "/tenants/95d19bda-09de-4d93-b7ae-acecd1e68186/providers/Microsoft.aadiam", "operationName": "Sign-in activity", "operationVersion": "1.0", "category": "NonInteractiveUserSignInLogs", "tenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "resultType": "0", "resultSignature": "None", "durationMs": 0, "callerIpAddress": "34.1.3.194", "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65", "identity": "User30", "Level": 4, "location": "US", "properties": {"id": "0f94f5fb-3583-4c46-9bfa-0390c1988800", "createdDateTime": "2023-01-12T19:22:14.5285742+00:00", "userDisplayName": "User30", "userPrincipalName": "user30@splunkresearch.com", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "appId": "4765445b-32c6-49b0-83e6-1d93765276ca", "appDisplayName": "OfficeHome", "ipAddress": "34.1.3.194", "status": {"errorCode": 0, "additionalDetails": "MFA requirement satisfied by claim in the token"}, "clientAppUsed": "Browser", "deviceDetail": {"deviceId": "", "operatingSystem": "Windows", "browser": "Rich Client 4.43.0.0"}, "location": {"city": "Boardman", "state": "Oregon", "countryOrRegion": "US", "geoCoordinates": {"latitude": 45.73722839355469, "longitude": -119.81143188476562}}, "mfaDetail": {}, "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65", "conditionalAccessStatus": "notApplied", "appliedConditionalAccessPolicies": [{"id": "SecurityDefaults", "displayName": "Security Defaults", "enforcedGrantControls": [], "enforcedSessionControls": [], "result": "success", "conditionsSatisfied": 3, "conditionsNotSatisfied": 0}], "authenticationContextClassReferences": [], "originalRequestId": "0f94f5fb-3583-4c46-9bfa-0390c1988800", "isInteractive": false, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails": [{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Oauth Scope Info", "value": "[\"OfficeHome.All\"]"}, {"key": "Is CAE Token", "value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none", "processingTimeInMilliseconds": 192, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName": "OfficeHome", "resourceId": "4765445b-32c6-49b0-83e6-1d93765276ca", "resourceTenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "homeTenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "authenticationDetails": [{"authenticationStepDateTime": "2023-01-12T19:22:14.5285742+00:00", "authenticationMethod": "Previously satisfied", "succeeded": true, "authenticationStepResultDetail": "MFA requirement satisfied by claim in the token", "authenticationStepRequirement": "Primary authentication"}], "authenticationRequirementPolicies": [{"requirementProvider": "user", "detail": "Per-user MFA"}], "authenticationRequirement": "multiFactorAuthentication", "servicePrincipalId": "", "userType": "Member", "flaggedForReview": false, "isTenantRestricted": false, "autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails": {}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "-_WUD4M1Rkyb-gOQwZiIAA", "authenticationStrengths": [], "incomingTokenType": "primaryRefreshToken", "authenticationProtocol": "none", "appServicePrincipalId": null, "resourceServicePrincipalId": null, "rngcStatus": 0}}
136+ example_log : ' {"time": "2023-01-12T19:22:14.5285742Z", "resourceId": "/tenants/95d19bda-09de-4d93-b7ae-acecd1e68186/providers/Microsoft.aadiam",
137+ "operationName": "Sign-in activity", "operationVersion": "1.0", "category": "NonInteractiveUserSignInLogs",
138+ "tenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186", "resultType": "0", "resultSignature":
139+ "None", "durationMs": 0, "callerIpAddress": "34.1.3.194", "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65",
140+ "identity": "User30", "Level": 4, "location": "US", "properties": {"id": "0f94f5fb-3583-4c46-9bfa-0390c1988800",
141+ "createdDateTime": "2023-01-12T19:22:14.5285742+00:00", "userDisplayName": "User30",
142+ "userPrincipalName": "user30@splunkresearch.com", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998",
143+ "appId": "4765445b-32c6-49b0-83e6-1d93765276ca", "appDisplayName": "OfficeHome",
144+ "ipAddress": "34.1.3.194", "status": {"errorCode": 0, "additionalDetails": "MFA
145+ requirement satisfied by claim in the token"}, "clientAppUsed": "Browser", "deviceDetail":
146+ {"deviceId": "", "operatingSystem": "Windows", "browser": "Rich Client 4.43.0.0"},
147+ "location": {"city": "Boardman", "state": "Oregon", "countryOrRegion": "US", "geoCoordinates":
148+ {"latitude": 45.73722839355469, "longitude": -119.81143188476562}}, "mfaDetail":
149+ {}, "correlationId": "fc78e38c-1e61-4be3-b47d-f3e6a9724a65", "conditionalAccessStatus":
150+ "notApplied", "appliedConditionalAccessPolicies": [{"id": "SecurityDefaults", "displayName":
151+ "Security Defaults", "enforcedGrantControls": [], "enforcedSessionControls": [],
152+ "result": "success", "conditionsSatisfied": 3, "conditionsNotSatisfied": 0}], "authenticationContextClassReferences":
153+ [], "originalRequestId": "0f94f5fb-3583-4c46-9bfa-0390c1988800", "isInteractive":
154+ false, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
155+ [{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Oauth Scope
156+ Info", "value": "[\"OfficeHome.All\"]"}, {"key": "Is CAE Token", "value": "False"}],
157+ "networkLocationDetails": [], "clientCredentialType": "none", "processingTimeInMilliseconds":
158+ 192, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn":
159+ "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName":
160+ "OfficeHome", "resourceId": "4765445b-32c6-49b0-83e6-1d93765276ca", "resourceTenantId":
161+ "95d19bda-09de-4d93-b7ae-acecd1e68186", "homeTenantId": "95d19bda-09de-4d93-b7ae-acecd1e68186",
162+ "authenticationDetails": [{"authenticationStepDateTime": "2023-01-12T19:22:14.5285742+00:00",
163+ "authenticationMethod": "Previously satisfied", "succeeded": true, "authenticationStepResultDetail":
164+ "MFA requirement satisfied by claim in the token", "authenticationStepRequirement":
165+ "Primary authentication"}], "authenticationRequirementPolicies": [{"requirementProvider":
166+ "user", "detail": "Per-user MFA"}], "authenticationRequirement": "multiFactorAuthentication",
167+ "servicePrincipalId": "", "userType": "Member", "flaggedForReview": false, "isTenantRestricted":
168+ false, "autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails":
169+ {}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "-_WUD4M1Rkyb-gOQwZiIAA",
170+ "authenticationStrengths": [], "incomingTokenType": "primaryRefreshToken", "authenticationProtocol":
171+ "none", "appServicePrincipalId": null, "resourceServicePrincipalId": null, "rngcStatus":
172+ 0}}'
0 commit comments