# \[Filebeat\] Azure Module - Additional Azure AD Log Sources

**URL:** https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026
**Category:** Beats
**Tags:** beats-module, filebeat
**Created:** [January 24, 2021, 8:34am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026 "2021-01-24T08:34:21Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Matthew\_Lubbers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_lubbers/32/78061_2.png) [@Matthew\_Lubbers](https://discuss.elastic.co/u/Matthew_Lubbers)
#### Post date: [January 24, 2021, 8:34am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/1 "2021-01-24T08:34:21Z")

</div>

Recently Microsoft Azure has added 4 new Azure AD log sources to be consumed by Azure Monitor Diagnostic Settings. When would be able to receive support for these new log sources for the Azure module?

New Log Sources

- NonInteractiveUserSignInLogs
- ServicePrincipalSignInLogs
- ManagedIdentitySignInLogs
- ProvisioningLogs

Thanks!

---

<div class="post-metadata">

### Author: ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)
#### Post date: [January 25, 2021, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/2 "2021-01-25T13:37:51Z")

</div>

hi @Matthew_Lubbers, can you create an enhancement issue in the beats github repo , [elastic/beats: Beats - Lightweight shippers for Elasticsearch & Logstash (github.com)](https://github.com/elastic/beats), this might be something we want to add in. Meanwhile, you could use the azure-eventhub input and use your own pipeline to process the messages.

---

<div class="post-metadata">

### Author: ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)
#### Post date: [January 25, 2021, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/3 "2021-01-25T14:16:07Z")

</div>

Thanks for the request @Matthew_Lubbers. As Mariana mentioned, it's best to create an enhancement requests. I've gone ahead and created the issue [here](https://github.com/elastic/beats/issues/23653).

If you could provide some sample events of the new SignIn and Provisioning logs in JSON format it'd be a big help (sanitised events are fine).

---

<div class="post-metadata">

### Author: ![opiedrah](https://avatars.discourse-cdn.com/v4/letter/o/5f9b8f/32.png) [@opiedrah](https://discuss.elastic.co/u/opiedrah)
#### Post date: [February 3, 2021, 12:16pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/4 "2021-02-03T12:16:37Z")

</div>

@jamie.hynds @jamie.hynds on a similar matter. Microsoft has a security graph Api to pull all security related events . Do you know if there is any work regarding integrating this data similar how you currently do the o365 module for the Microsoft management Api?  
Thank you

---

<div class="post-metadata">

### Author: ![Matthew\_Lubbers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_lubbers/32/78061_2.png) [@Matthew\_Lubbers](https://discuss.elastic.co/u/Matthew_Lubbers)
#### Post date: [February 3, 2021, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/5 "2021-02-03T20:50:18Z")

</div>

For reference, here is the Graph API documentation for security alerts:  
[MSFT Graph API - Security Alerts](https://docs.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0)

In my opinion, I would skip the Secure Score APIs as they are pretty subjective and most of the time, enterprises use a Cloud Security Posture Management (CSPM) tool to provide compliance across Cloud Platforms instead of just relying on Secure Score.

---

<div class="post-metadata">

### Author: ![opiedrah](https://avatars.discourse-cdn.com/v4/letter/o/5f9b8f/32.png) [@opiedrah](https://discuss.elastic.co/u/opiedrah)
#### Post date: [February 4, 2021, 3:22am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/6 "2021-02-04T03:22:03Z")

</div>

I would agree, the securityevents is what matters. I reviewed in detail the filebeat o365 module that leverages the microsoft management api. It has some alerts from the securitycompliance scheme but it is missing many other alerts such as the identity protection alerts.

> [@Microsoft Graph Security API integration](https://discuss.elastic.co/t/microsoft-graph-security-api-integration/263074):
>
> Filebeat has an o365 module that connects to the Microsoft Management API. Does anyone if there are working or is there a connector available for the Microsoft Graph Security API [Microsoft Graph Security API overview - Microsoft Graph | Microsoft Docs](https://docs.microsoft.com/en-us/graph/security-concept-overview) Thank you

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 4, 2021, 5:22am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/7 "2021-03-04T05:22:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
