Hello,
I been leveraging Azure Logs - Audit Logs to collect Azure AD data.
This is have been alright but I wanted to test out the Microsoft Entra ID Entity Analytics, wondering if others' experience with the latter integration.
Hello,
I been leveraging Azure Logs - Audit Logs to collect Azure AD data.
This is have been alright but I wanted to test out the Microsoft Entra ID Entity Analytics, wondering if others' experience with the latter integration.
Hello,
W've been using it and it's awesome for a lot of reasons.
Something you need to be aware of, is the different timestamps. Depending on the dataview you create the data can visualise in total different ways, because it takes the ingest timestamp vs the asset created timestamp vs the asset last signin timestamp.
There is definitely room for improvement. Some examples:
It only contains Entra ID devices, not Intune data. Hopefully Elastic will release an Intune Entity Analyticvs dataset soon.
What we kind of need is an easy! way to compare datasets. I'm having a hard time to compare the Entra ID Device dataset with other datasets, so we can detect, for example, which hosts are missing a certain agent.
WillemD
Thanks!
Yeah I don't like how the Microsoft hides information, we had a similar issue with subscriptions only showing up as subscription.id which didn't help that much until we enriched it using an ingest pipeline.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.