# \[Filebeat\] Azure Module - Additional Azure AD Log Sources

**URL:** <https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [January 24, 2021, 8:34am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026 "2021-01-24T08:34:21Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![opiedrah](https://avatars.discourse-cdn.com/v4/letter/o/5f9b8f/32.png) [@opiedrah](https://discuss.elastic.co/u/opiedrah)\
**Post date:** [February 4, 2021, 3:22am UTC](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026/6 "2021-02-04T03:22:03Z")

</div>

I would agree, the securityevents is what matters. I reviewed in detail the filebeat o365 module that leverages the microsoft management api. It has some alerts from the securitycompliance scheme but it is missing many other alerts such as the identity protection alerts.

> [@Microsoft Graph Security API integration](https://discuss.elastic.co/t/microsoft-graph-security-api-integration/263074):
>
> Filebeat has an o365 module that connects to the Microsoft Management API. Does anyone if there are working or is there a connector available for the Microsoft Graph Security API [Microsoft Graph Security API overview - Microsoft Graph | Microsoft Docs](https://docs.microsoft.com/en-us/graph/security-concept-overview) Thank you

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-azure-module-additional-azure-ad-log-sources/262026)._
