Microsoft Intune Logs (Beta)

Connecting Microsoft Intune logs to your Panther Console

Overview

Microsoft Intune log ingestion is in open beta starting with Panther version 1.114, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther supports ingesting Microsoft Intune logs via the Azure Event Hub Data Transport.

How to onboard Microsoft Intune logs to Panther

You'll first create an Azure Event Hub source in Panther, then configure Azure to export logs to that location.

Prerequisites

Before onboarding Microsoft Intune logs to Panther, ensure that:

Step 1: Create a new Microsoft Intune source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Microsoft Intune” then click its tile.

  4. On the slide-out panel, click Start Setup.

    An arrow is drawn from a tile in the background titled "Microsoft Intune" to a Start Setup button.
  5. Follow Panther's instructions for configuring an Azure Event Hub.

Step 2: Export Intune logs to the Event Hub

To export Microsoft Intune logs to an Event Hub, follow the instructions below.

For additional support, see the Microsoft Send Intune log data to Azure Storage, Event Hubs, or Log Analytics documentation.

  1. In your Azure Portal, navigate to the Intune admin center at https://intune.microsoft.com/.

  2. In the navigation bar, click Diagnostics settings.

  3. Click + Add diagnostic setting.

    Under a "Diagnostics settings" title, an arrow is drawn from a "Diagnostics settings" navigation bar item to an "+ Add diagnostic setting" link.
  4. Fill in the fields:

    1. In the Diagnostic setting name field, enter a descriptive name.


    2. Under Destination details, click the Stream to an event hub checkbox.

    3. In the Event hub field, select the Event Hub namespace and Event Hub you onboarded in Step 1.

    4. Under Log, select all log types you would like to ingest in Panther.

  5. Click Save.

Supported log types

MicrosoftIntune.AuditLogs

MicrosoftIntune.Devices

MicrosoftIntune.DeviceComplianceOrg

MicrosoftIntune.OperationalLogs

MicrosoftIntune.Windows365AuditLogs

Last updated

Was this helpful?