Azure Monitor in External Tenant

Ken Korczynski 5 Reputation points
2025-02-06T18:36:03.27+00:00

Hi, We are setting up an Entra External ID tenant to house external users of a web app that we host. I presently stream our internal diagnostics logs to an Event Hub in our workforce tenant and then to an IDR. I found this article and was successful at setting up sending diagnostics to a LogAnalytics workspace, but can't for the life of me get it to send to my Event Hub. I set up a Shared access policy, but I think I am missing the delegation for Azure Event Hubs Data Sender in Lighthouse, but have not been able to create the correct ARM template. Has anyone been down this road? Thanks Ken

https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-azure-monitor

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,484 questions
Azure Lighthouse
Azure Lighthouse
An Azure service that provides secure managed services and access control for partners and customers.
84 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Vinod Pittala 330 Reputation points Microsoft Vendor
    2025-02-06T22:02:41.48+00:00

    Hello Ken Korczynski,

    Welcome to Microsoft Q&A Forum, thank you for posting your query here!

    I understand that you are intended to send the logs from external tenant to Azure Event hub.

    In this approach, as how you have been succeeded in sending logs to log analytics workspace using the Diagnostic settings, you can follow the same method to send logs to Even hub. and understood that you are using Azure Lighthouse to delegate a resource, which typically allows your external tenant to manage a workforce tenant resource.

    So, once the customer has been onboarded, authorize the users by deploying an Azure Resource Manager template to the subscription that contains Azure Event Hub.

    After this authorization is completed, the subscription and Event Hub can be selected as a target in the Diagnostic settings in external tenant.

    The below article shows how you can stream your logs to an event hub by using one of the SIEM tools.

    https://learn.microsoft.com/en-us/entra/identity/monitoring-health/howto-stream-logs-to-event-hub?tabs=splunk

    Once you have the Azure event hub ready, navigate to the any one of the SIEM tool that you want to integrate with the activity logs. so that you can send the logs to Azure event hub.

    Hope this helps!

    Please reply if you have any challenges.

    Please do not forget to “upvote it” wherever the information provided helps you, this can be beneficial to other community members.it would be greatly appreciated and helpful to others.

    Thanks

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.