Comments (5)
After fixing the first error by renaming the index pattern ID , one of the dashboard saved searches started working , which is o365 alerts
But the issue seems to be with the remaining ones that are using user.id.keyword and client.ip.keyword.
Any help on this is appreciated. Thanks in advance.
from o365beat.
@Rajprince2793 please how do you make a connection with Azure API
can you send me please your config file and all steps to fixe my issues ?
please contat me [email protected]
from o365beat.
@aymenwerg If you're having trouble with the O365 beat config file , you can reference this link below
https://vizion.ai/forum/topic/o365beat-for-windows/
Make sure a custom application ( for SIEM ) is created on Azure AD by following the steps here
Below is the key piece of the config that you need to obtain from the app you configured
tenant_domain: ${O365BEAT_TENANT_DOMAIN:your tenant domain here}
client_secret: ${O365BEAT_CLIENT_SECRET:your client secret here}
client_id: ${O365BEAT_CLIENT_ID:your client id here} # aka application id (GUID)
directory_id: ${O365BEAT_DIRECTORY_ID:your directory id here} # aka tenant id (GUID)
registry_file_path: ${O365BEAT_REGISTRY_PATH:./o365beat-registry.json}
from o365beat.
@chris-counteractive Must have missed to tag you on the post , sorry about that
from o365beat.
In researching another issue, I realized (a few months late) that filebeat now supports o365 with an official module, as of v7.7.0. It supports a variety of visualizations out of the box, and will surely stay more current with the latest updates to the Elastic Stack, including Kibana.
Given there's an "official solution" to visualization, I'm going to close this issue, please let me know if you have any further questions. Thanks!
from o365beat.
Related Issues (20)
- Exiting: error loading config file: yaml: line 2: did not find expected node content HOT 5
- Understanding Authentication Data HOT 4
- visualization not working HOT 5
- Client.Timeout for Exchange/General/Sharepoint HOT 6
- Docker Instructions HOT 3
- Parsing Extended Properties HOT 4
- Preventing Duplicate Events HOT 4
- Logstash connection errors HOT 7
- o365 audit.exchange not returning threat audit logs HOT 3
- WARN beater/o365beat.go:249 start XX must be <=YY hrs ago, resetting HOT 3
- Live Realoding Credentials HOT 2
- Proxy support for the API requests HOT 1
- Certificate signed by unknown authority message HOT 2
- AzureActiveDirectory Logs not pulled HOT 3
- Log content changed recently?
- GCC High no available content locations: HOT 1
- Tenant ID not found
- Does O365beat support multiple Office 365 tenants scenario
- Log file is not getting created
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from o365beat.