# Azure & Office 365, Oh My

**URL:** <https://discuss.elastic.co/t/azure-office-365-oh-my/161574>\
**Category:** Logstash\
**Created:** [December 19, 2018, 5:54pm UTC](https://discuss.elastic.co/t/azure-office-365-oh-my/161574 "2018-12-19T17:54:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![randomuserid](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@randomuserid](https://discuss.elastic.co/u/randomuserid)\
**Post date:** [December 19, 2018, 5:54pm UTC](https://discuss.elastic.co/t/azure-office-365-oh-my/161574/1 "2018-12-19T17:54:43Z")

</div>

Is there a "good" way to ingest logs from Azure, Azure AD and / or Office 365 via logstash? I have just been handed these requirements..

---

<div class="post-metadata">

**Author:** ![patrickmm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrickmm/32/39009_2.png) [@patrickmm](https://discuss.elastic.co/u/patrickmm)\
**Post date:** [December 19, 2018, 7:45pm UTC](https://discuss.elastic.co/t/azure-office-365-oh-my/161574/2 "2018-12-19T19:45:55Z")

</div>

I started working on this issue with Microsoft's Cloud App Security logs last week. I'm not sure about other Microsoft log sources, but CAS logs are exported in CEF format. As of right now, I'm looking at parsing CAS logs via a logstash pipeline.

I'll post an update here as soon as I have something to share.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2019, 7:45pm UTC](https://discuss.elastic.co/t/azure-office-365-oh-my/161574/3 "2019-01-16T19:45:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
