教程:将 Azure Active Directory 日志流式传输到 Azure 事件中心Tutorial: Stream Azure Active Directory logs to an Azure event hub

本教程介绍如何设置 Azure Monitor 诊断设置,以便将 Azure Active Directory (Azure AD) 日志流式传输到 Azure 事件中心。In this tutorial, you learn how to set up Azure Monitor diagnostics settings to stream Azure Active Directory (Azure AD) logs to an Azure event hub. 根据此机制将日志与 Splunk 和 QRadar 等第三方安全信息和事件管理 (SIEM) 工具集成。Use this mechanism to integrate your logs with third-party Security Information and Event Management (SIEM) tools, such as Splunk and QRadar.

先决条件Prerequisites

若要使用此功能,需满足以下条件:To use this feature, you need:

  • Azure 订阅。An Azure subscription. 如果没有 Azure 订阅,可以注册试用版If you don't have an Azure subscription, you can sign up for a trial.
  • Azure AD 租户。An Azure AD tenant.
  • 一个是 Azure AD 租户的全局管理员或安全管理员的用户。 A user who's a global administrator or security administrator for the Azure AD tenant.
  • 在 Azure 订阅中有事件中心命名空间和事件中心。An Event Hubs namespace and an event hub in your Azure subscription. 了解如何创建事件中心Learn how to create an event hub.

将日志流式传输到事件中心Stream logs to an event hub

  1. 登录到 Azure 门户Sign in to the Azure portal.

  2. 选择“Azure Active Directory” > “监视” > “审核日志”。 Select Azure Active Directory > Monitoring > Audit logs.

  3. 选择“导出设置”。Select Export Settings.

  4. 在“诊断设置”窗格中,执行下述操作之一:In the Diagnostics settings pane, do either of the following:

    • 若要更改现有设置,请选择“编辑设置”。To change existing settings, select Edit setting.

    • 若要添加新设置,请选择“添加诊断设置”。To add new settings, select Add diagnostics setting.
      最多可以有三个设置。You can have up to three settings.

      导出设置

  5. 选中“流式传输到事件中心”复选框,然后选择“事件中心/配置”。Select the Stream to an event hub check box, and then select Event Hub/Configure.

  6. 选择要将日志路由到的 Azure 订阅和事件中心命名空间。Select the Azure subscription and Event Hubs namespace that you want to route the logs to.
    订阅和事件中心命名空间必须都与从其流式传输日志的 Azure AD 租户相关联。The subscription and Event Hubs namespace must both be associated with the Azure AD tenant that the logs stream from. 也可在应将日志发送到的事件中心命名空间中指定一个事件中心。You can also specify an event hub within the Event Hubs namespace to which logs should be sent. 如果未指定事件中心,则会使用默认名称 insights-logs-audit 在命名空间中创建一个事件中心。If no event hub is specified, an event hub is created in the namespace with the default name insights-logs-audit.

  7. 选择“确定”,退出事件中心配置。Select OK to exit the event hub configuration.

  8. 执行下列两项操作或之一:Do either or both of the following:

    • 若要将审核日志发送到事件中心,请选中“AuditLogs”复选框。To send audit logs to the event hub, select the AuditLogs check box.
    • 若要将登录日志发送到事件中心,请选中“SignInLogs”复选框。To send sign-in logs to the event hub, select the SignInLogs check box.
  9. 选择“保存”,保存设置。Select Save to save the setting.

    诊断设置

  10. 大约 15 分钟后,验证事件是否显示在事件中心。After about 15 minutes, verify that events are displayed in your event hub. 为此,请从门户转到事件中心,然后验证“传入消息”计数是否大于零。To do so, go to the event hub from the portal and verify that the incoming messages count is greater than zero.

    审核日志

从事件中心访问数据Access data from your event hub

数据显示在事件中心以后,即可通过两种方式来访问和读取数据:After data is displayed in the event hub, you can access and read the data in two ways:

后续步骤Next steps