Microsoft Intune Logs (Beta)
Connecting Microsoft Intune logs to your Panther Console
Overview
Panther supports ingesting Microsoft Intune logs via the Azure Event Hub Data Transport.
How to onboard Microsoft Intune logs to Panther
You'll first create an Azure Event Hub source in Panther, then configure Azure to export logs to that location.
Prerequisites
Before onboarding Microsoft Intune logs to Panther, ensure that:
You have an Azure subscription and your user has an Owner or Contributor role.
You have an already created Event Hubs namespace and Event Hub (as specified in the Event Hub Source prerequisites).
Step 1: Create a new Microsoft Intune source in Panther
In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.
Click Create New.
Search for “Microsoft Intune” then click its tile.
On the slide-out panel, click Start Setup.

Follow Panther's instructions for configuring an Azure Event Hub.
Step 2: Export Intune logs to the Event Hub
To export Microsoft Intune logs to an Event Hub, follow the instructions below.
In your Azure Portal, navigate to the Intune admin center at https://intune.microsoft.com/.
In the navigation bar, click Diagnostics settings.
Click + Add diagnostic setting.

Fill in the fields:
In the Diagnostic setting name field, enter a descriptive name.
Under Destination details, click the Stream to an event hub checkbox.

In the Event hub field, select the Event Hub namespace and Event Hub you onboarded in Step 1.
Under Log, select all log types you would like to ingest in Panther.
Click Save.
Supported log types
MicrosoftIntune.AuditLogs
MicrosoftIntune.Devices
MicrosoftIntune.DeviceComplianceOrg
MicrosoftIntune.OperationalLogs
MicrosoftIntune.Windows365AuditLogs
Last updated
Was this helpful?

