For the complete documentation index, see llms.txt. This page is also available as Markdown.

ADAudit Plus

Connect ManageEngine ADAudit Plus to Radiant Security to forward Active Directory audit events for AI triage.

ManageEngine ADAudit Plus is an Active Directory auditing and reporting tool that detects insider threats, privilege misuse, and unauthorized changes across AD, Azure AD, file servers, and Windows endpoints.

Connecting ADAudit Plus forwards logon activity, account management changes, and policy change events to Radiant Security via Radiant's HTTPS webhook endpoint. Radiant uses these events to enrich alerts during AI triage, giving analysts visibility into the directory-layer context behind a suspicious sign-in or privilege change.

Prerequisites

Add the data connector in Radiant Security

  1. Log in to Radiant Security.

  2. From the navigation menu, select Settings > Data Connectors and click + Add Connector.

  3. Search for and select ADAudit Plus Webhook, then click Data Feeds.

  4. Under Select your data feeds, select ADAudit Plus Webhook and click Credentials.

  5. In the Credential Name field, enter an identifiable name for this credential (e.g., ADAudit Plus Integration).

  6. Under Required Credentials, enter a value in the Connector tag field. This can be any string. Radiant uses this value as salt when generating the authentication token for your connector.

  7. Click Add Connector.

  8. Open the newly created connector. Under Vendor Configuration, copy and save the Webhook URL and Token values. You will need both in the next section.

Configure ADAudit Plus to forward events via HTTPS

ADAudit Plus's Splunk HTTP Event Collector forwarder is compatible with Radiant's webhook endpoint. Configure it with the Webhook URL and Token you copied from Radiant.

  1. In the ADAudit Plus Control Panel, click the Admin tab.

  2. In the side panel, select Configuration > SIEM Integration.

  3. Select the Enable forwarding of ADAuditPlus Data checkbox.

  4. Click the Splunk HTTP tab and enter the following values:

    • Splunk Server: the Webhook URL value copied from Radiant.

    • HTTP Event Collector port: 443

    • SSL Enabled: True

    • Authentication Token: the Token value copied from Radiant.

    • Folder size threshold: 5 GB

    • Leave Enable Log forwarding of ADAudit Plus application logs unselected.

    • Select Yes, I agree that it is compliant.

  5. Click Save.

  6. On the right side, click Choose Categories to forward.

  7. Select all categories except AzureAD Logon Reports and AzureAD Management Reports.

  8. Click Save.

Verify ingestion

After ADAudit Plus begins forwarding, confirm events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"ad_audit_webhook".

  3. Confirm recent events appear.

Allow several minutes for events to be parsed, indexed, and available for search.

Last updated

Was this helpful?