Getting Data In

Splunk and Microsoft Advanced Threat Analytics

alonsocaio
Contributor

Is there any way to integrate and send Microsoft Advanced Threat Analytics events to Splunk?

0 Karma
1 Solution

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

View solution in original post

25D55AD2
Engager

But are these logs well parsed by default by Splunk?

alonsocaio
Contributor

Yes, they are. I have created a custom sourcetype for MS ATA so I could extract more fields, but It is well parsed since It has field : value in its logs and also have some delimiters.

0 Karma

alonsocaio
Contributor

Actually I found a solution. Microsoft ATA can send Syslog alerts to any SIEM server.

edhealea
Path Finder

Where you able to get this to work? I have added my syslog server into the ATA config under the syslog server setting but I am not getting any alerts. I can generate a test message and receive it in our syslog server.

alonsocaio
Contributor

I have configured Syslog Server Endpoint (server:port), Transport (UDP) and Format (RFC 5424), following the docs. Take a look at the Notifications menu and go to Syslog Notifications. Check if all options are enabled.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...