Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Device details in the logs from Jumpcloud to sentinel are missing in randam sso event logs #11535

Open
harishmenti opened this issue Dec 8, 2024 · 5 comments
Assignees
Labels
Parser Parser specialty review needed

Comments

@harishmenti
Copy link

Hi Team,

We have integrated Jump Cloud with Sentinel to forward all the logs to Sentinel using the function app with the code found in GitHub. We've been encountering a few logs with missing device details and IP addresses, leading to incident creation ( as we have custom rules to compare IPs against device details). We contacted Jumpcloud, and they stated it was not their responsibility to troubleshoot since the data connector was developed and managed by Azure.. Image

@v-sudkharat v-sudkharat added Parser Parser specialty review needed and removed Log Analytics labels Dec 10, 2024
@v-sudkharat
Copy link
Contributor

Hi @harishmenti, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!

@v-sudkharat
Copy link
Contributor

v-sudkharat commented Dec 12, 2024

@harishmenti, want to confirm, is this a path for function app -https://github.com/Azure/Azure-Sentinel/tree/5891abc456cd8cceb0b724a9f737b81aae67298a/DataConnectors/JumpCloud%20Single%20Sign%20On which has been configured?
And, can you please check if those logs (device details and IP addresses) are available in source itself? could you please share the logs with us, to understand the issue. Thanks!

@harishmenti
Copy link
Author

harishmenti commented Dec 12, 2024 via email

@v-sudkharat
Copy link
Contributor

@harishmenti, Not able to see the logs here, can you plz share it on this mail ID - v-sudkharat@microsoft.com

@harishmenti
Copy link
Author

harishmenti commented Dec 12, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Parser Parser specialty review needed
Projects
None yet
Development

No branches or pull requests

4 participants