Set up ADAudit Plus to forward security events to Radiant Security via HTTPS.
Overview
In this guide, you will set up ADAudit Plus to forward security events to Radiant Security's HTTPS connector. The security events are used to identify suspicious activity within the environment related to User Logon Activity, Account Management and Policy Changes.
Prerequisites
- Admin access to ADAudit Plus Control Panel
Add the data connector in Radiant Security
Configure ADAudit Plus to forward events via HTTPS
On the ADAudit Control Panel:
- Click the Admin tab.
- On the side panel, select Configuration and SIEM Integration.
- Select the Enable forwarding of ADAuditPlus Data checkbox.
- Click the Splunk HTTP tab and fill in the following details:
- Splunk Server Name: Paste the Webhook URL value that you previously copied from Radiant Security’s connector page
- HTTP Event Collector Port:
443
- SSL Enabled:
True
- Authentication Token: Paste the Token value that you previously copied from Radiant Security’s connector page
- Folder size threshold:
5 GB
- Leave the Enable Log forwarding of ADAudit Plus application logs checkbox unselected.
- Select the Yes, I agree that it is compliant checkbox.
- Click Save.
- On the right side, click Choose Categories to forward.
- Select all checkboxes except for AzureAD Logon Reports and AzureAD Management Reports. Those categories can be collected directly from Microsoft Connectors.
- Click Save.
We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai
Last updated: 2024-08-23