siem
siem copied to clipboard
The repository contains artifacts to create and publish reports, alerts, and dashboards based on Azure AD B2C logs. These artifacts can also be used for Security Information & Event Management (SIEM)...
Issue: 1. Log analytics funnels assume "user_Id" property is present on root level of the telemetry event to correlate users in the funnel. 2. AzureApplicationInsightsProvider does not allow arbitrary fields...
In the dashboard for errors table, we only see "Invalid username and password" error even though there are different errors happened within the custom journey steps. App Insights show these...
 The link to Conditional Access workbook should be `Conditional Access` or `CA` not `MFA`. Additionally, the link to Conditional Access is not found.
**Not able to use command for rgDelegatedResourceManagement though it get sucessful if done through clicking on deploy button in this repo readme which open template in azure UI**  ...
When you try to deploy the 'MFA' workbook using the "Deploy to Azure" button it is currently deploying the "conditional access workbook. The correct MFA workbook can be found here:...