Sept. 15, 2023, 4:09 p.m. | /u/Man-of-Geek

cybersecurity www.reddit.com

Hi All,

Some context, our company decided a commercial SIEM (Splunk) was no longer affordable and switched us to Security Onion. I am looking at how to integrate the Azure AD logs into SO but the documentation is not much out there.

Anyone have any links or suggestions on how to easily do this?

azure azure ad commercial context cybersecurity documentation integrate links logs onion security siem splunk

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Associate Principal Security Engineer

@ Activision Blizzard | Work from Home - CA

Security Engineer- Systems Integration

@ Meta | Bellevue, WA | Menlo Park, CA | New York City

Lead Security Engineer (Digital Forensic and IR Analyst)

@ Blue Yonder | Hyderabad

Senior Principal IAM Engineering Program Manager Cybersecurity

@ Providence | Redmond, WA, United States

Information Security Analyst II or III

@ Entergy | The Woodlands, Texas, United States