Skip to main content
Sumo Logic

Lab 1 - Azure Ad hoc investigation using Live Tail

This lab give you practical experience to use metadata and keywords to narrow your search scope and improve performance for a security context.

In this lab, you will learn the use of metadata and keywords to narrow your search scope and improve performance. You will also do an ad hoc investigation using real time log data with Live Tail

Edit section

When you narrow your search as a best practice, your monthly data ingested could be reduced. reduced. Also, a query using keywords will run faster as it may have less data to examine.


Using Live Tail
  1. First let's just get familiar with our incoming Active Directory data using a simple scoping line that isolates specifically Active Directory incoming data. Search for all messages for the last 15 min with _sourceCategory=Labs/Azure/AD.

    _sourceCategory=Labs/Azure/AD
  2. Now, to further improve the query performance and keep your ingesting data optimal, let's narrow your search down. Let's search for only incoming messages that contain the keyword administrator by adding the keyword administrator at the end.
    _sourceCategory=Labs/Azure/AD and administrator
  3. To locate the keyword administrator in the log message results, you will need to expand properties by clicking on the arrow expander to the right of properties, . You will now see administrator highlighted at this nested level. 
    clipboard_e33085784ca9ef177b6758ff7233608e5.png
  4. Keywords are case insensitive. To show this replace administrator with Administrator, or ADMINISTRATOR, and re-running the query.
    _sourceCategory=Labs/Azure/AD and ADMINISTRATOR
  5. Using wildcards can be helpful. Let's search for messages across all your Azure data that contain the word "administrator".  To locate the keyword administrator in the log message results, you will need to expand properties by clicking on the drop down. You will see administrator highlighted at this nested level. 
    sourceCategory=Labs/Azure/* and administrator
    clipboard_e6a678548f1355b0a62e8e9b5a5f2a5a5.png
  6. There is another way to look at the nested JSON hierarchy in the log messages. In the middle right, click Expand JSON. You will see your nested levels all expanded for JSON display. You can toggle back using click Collapse JSON. Also try clicking View as Raw, if you don't care to see it displayed in JSON format. 

  7. For security reasons you may want to quickly monitor incoming data as it is being ingested. Using the last query, run a Live Tail session. Click Live Tail. There currently is a limit of 10 concurrent Live Tail sessions per organization. For more help on troubleshooting Live Tail look here.

  8. Just as we expanded in the messages to look at administrator, perhaps you want to see all administrator coming in with their associated userName'sWe offer highlighting in Live Tail. Click on the A button in the upper right and type administrator and press Enter, then type username and press Enter. Just like Keywords, metadata has no case sensitivity.
    clipboard_ecf85f52b1691347d11221e544bf9fc01.png

  9. Click any where in the Live Tail window to observe the highlights clearly and the entry box will close. Maybe you want to pause the tail before the administrator disappears off the screen?  To do this, at the upper right, click Pause Screen Shot 2020-04-08 at 2.10.41 PM.png and then to resume click Jump to Bottom Screen Shot 2020-04-08 at 2.12.56 PM.png or Screen Shot 2020-04-08 at 2.13.27 PM.png.

  10. To disable the highlighted text, click the A button and click on the x.
    clipboard_ee619796dbc8839d8c7170227d077128b.png

  11. Often we may want to see a specific user's activity. You can track a administrator found in this query's data source to another incoming data source. You can run up to 2 Live Tail session in a browser. To compare these results with another source of data using Live Tail, click on the 3 vertical dots on the upper right of the Live Tail window and select Split Screen. This allows you to run two Live Tails at the same time. Enter _sourceCategory=labs/azure/audit  Split screen is helpful in general for an adhoc type of analysis.
    clipboard_ebbdc1c19f75d1c568c9e812e562a67cd.png
  12. To close the Live Tail you can either click on the 3 vertical dots and select Stop Live Tail, or just close out the browser tab by clicking on the X