Forum Discussion

Manuel_DEste's avatar
Manuel_DEste
Copper Contributor
Jan 09, 2020

Export Active directory Identity protection Risky user events to EventHub/ SIEM

Dear community,

I cannot find the Risky user events "User at risk detected" on Azure Activity Logs, Sign-in Logs or Audit Logs. 

Are these events being logged somewhere?

 

I'm looking for a way to export or stream this type of events to EventHub so I can then pull or ingest the events into a 3rd Party SIEM solution (i.e. SPlunk, QRadar)

 

Thank you for your help!

Resources