Logo
Sign in
  1. Logpoint Service Desk
  2. Products Hub
  3. Marketplace

 

default.png

Microsoft Graph

Microsoft Graph is a Universal Rest API based log source template that enables you to fetch and analyze logs from Microsoft Graph. 

Release Details
Version: 5.3.1
Release date: 08 May, 2025
Supported On: Logpoint v7.4.0 and later
Documentation: Microsoft Graph Guide
SHA 256: 26e193e8edd83245fb9b3290f397c9e544d76519b9fbf531ec9714217692fbb9
Download

Package Details

Microsoft Graph API consists of the following components:

  1. Universal REST API Fetcher
    • MicrosoftGraphFetcher
  2. Compiled Normalizer
    • MicrosoftGraphCompiledNormalizer
  3. Search Templates
    • Entra ID Identity Protection
    • Defender XDR Security
  4. Dashboards
    • LP_DEFENDER XDR ALERTS
    • LP_DEFENDER XDR INCIDENTS
    • LP_ENTRA ID IDENTITY PROTECTION
  5. Alerts
    • LP_Microsoft Defender XDR - High Severity Alert
    • LP_Microsoft Defender XDR - Host Generating Multiple Alerts
    • LP_Microsoft Defender XDR - Multiple Alerts Involving Same User
    • LP_Microsoft EntraID - User at Risk
    • LP_Potentially Unwanted Software Detected
  6. Report Template
    • Entra ID Audit Activity Monitoring

Bug Fix

Description Issue Id Reference Id
MicrosoftGraph Compiled Normalizer didn't normalize logs forwarded via Syslog Forwarder, resulting in missed logs and alerts.

PLUG-15724

86733

 

Past Releases

Microsoft Graph v5.3.0

Version: 5.3.0
Release date: 30th October, 2024
Supported On: Logpoint v7.4.0 or later
Documentation: Microsoft Graph Guide
SHA 256:58e1ca2452ad0bfdfeb38fbb99793be62812b257d0ee790e08e4fb1c75253d22
Download

 

Enhancements

 

Description Issue Id Reference Id

MicrosoftGraphCompiledNormalizer is updated to map the following Microsoft Graph fields to the Logpoint fields. 

Microsoft Graph Field
Logpoint Field
accountName account
domainName domain
userSid user_sid
fileName file
filePath file_path
ipAddress source_address

PLUG-12017

84875

Microsoft Graph v5.2.0

Version: 5.2.0
Release date: 2024-07-17
Supported On: Logpoint v7.4.0 or later
Documentation: Microsoft Graph Guide
SHA 256: 0c4dfce688a97b44acc1321f8f367e56000628702d165811df29b16e3e2c2ba8
Download

 

Enhancements

 

Description Issue Id Reference Id

Microsoft Graph now includes two new endpoints:

  • auditLogs/directoryaudits
  • auditLogs/signIns

for collecting logs from Microsoft Entra ID, previously Azure Active Directory.

To learn more, go to Microsoft Graph.

KB-25090 -

Microsoft Graph now includes Dashboards, Search Templates, Alerts, and a Report Template, providing deeper insights into Microsoft Graph activities and security events.

To learn more, go to Microsoft Graph Analytics.

KB-25090, KB-24409, KB-23895, KB-24519 -

Microsoft Graph v5.1.0

Release date:2024-05-09
Supported On: Logpoint v7.4.0 or later
SHA 256: bfa052cc5f42b60103b33aba41f978a4261e058335529cb09ae751615bb011e1
Download: MicrosoftGraph_5.1.0.pak

Support

If you have any questions or require assistance, create a support ticket.

Comments

Article is closed for comments.

Follow

Related articles

  • Universal REST API Fetcher
  • Universal Normalizer
  • Microsoft Defender ATP
  • SentinelOne
  • AWSServices
Privacy policy    EULA    Terms of service   
Copyright © , Logpoint. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.