Prerequisites
To follow these instructions, you’ll need:
- Azure subscription.
- A Microsoft Entra ID tenant.
- A user account that is a Global Administrator or Security Administrator for the Microsoft Entra ID tenant.
Configure Azure Event Hubs
To stream events from Microsoft Entra ID to Event Hubs, you need to:
- Create a resource group in Azure Portal.
- Create an Event Hubs namespace within the new resource group.
- Create an event hub in the new namespace.
- Configure Microsoft Entra ID to stream logs to the new event hub.
- Retrieve the connection string for your new event hub.
- Send the connection string and consumer group name to SOC.