1. Describe your incident:
We have a Graylog with several input, but now we want to add events from Microsoft Defender (Via Azure Event Hub) We have installed the latest Graylog and we’ve added the Azure Event Hub input. But the input we get doesn’t add the properties from the Event Hub. We only get the information in the screenshot, but nothing else in Graylog. We have contacted Microsoft and according to them, they send all the information to the Graylog but Graylog doesn’t handle it.
This is all the information Graylog gives us
2. Describe your environment:
OS Information:
Linux 5.4.0-104-generic
Package Version:
4.3.7
Service logs, configurations, and environment variables:
3. What steps have you already taken to try and solve the problem?
Tried to get an answer from the community, and have had help from Microsoft to make sure that the logs are sent from them.
4. How can the community help?
Someone who has done this and get events from Azure Event Hub?
I personal have not use the input " Azure Log Events" But I might be able to help troubleshoot your issue.
Can I ask why your using Azure Event Hub to get logs from Microsoft Defender?
Have you tried using a log shipper and sending those messages directly to Graylog?
Looks like the logs are arriving to the Graylog server. Can you tell use in greater detail what you mean “Graylog doesn’t handle it.”? What are you expecting to happen?
Can I ask why your using Azure Event Hub to get logs from Microsoft Defender?
Since we have a customer that want to use Azure and defender as a platform, but we don’t really want to use Sentinel since we have graylog for every other customer.
Looks like the logs are arriving to the Graylog server. Can you tell use in greater detail what you mean “Graylog doesn’t handle it.”? What are you expecting to happen?
Yeah, well all the information that graylog presents to us is in the screenshot, but when we look at the logs from Microsoft, we get plenty more output (Ip, what kind of threat, if it’s handled and so forth) but none of that shows up in graylog.
I will check the link and see if that’s something we can use