How to setup your AgileBlue integration within Azure.
Event Hub Creation
- Log into your Azure Portal.
- Select "Resource Group" from the left-hand menu and click "Add" at the top of the page.
- Select the correct subscription and region, then give the Group a unique name.
- Click on "Create Tags" and then "Review and Create."
- Tag creation is optional.
- With the Resource Group created, proceed to "All Services" to create the Event Hub Name Space.
- Click "Add" in the upper left-hand portion of the screen.
- Give the Event Hub the previously-created Resource Group and provide a name for the Name Space. For Pricing, Basic or Standard are acceptable.
- Click "Review + Create" and then "Create" when the hub is validated, or click "Next" if tags need to be created, then proceed to review and create and wait for deployment to complete.
- Once the deployment is finished, click "Go to resource" and verify the namespace is properly created.
- Now that the name space is created, proceed to create the event hub for log collection.
- Once on the Event-Hubs page, click "+ Event Hub".
- These steps will be repeated for:
- Activity Logs
- Sign-in Logs/Audit Logs
- Optional – Platform Logs
- Optional – Endpoint Logs
- These steps will be repeated for:
- Provide the name of the event hub.
- Once the hubs have been completed, the list should look similar to the image below.
- AzureAD-Logs will contain the logs for Audit and Sign-In
- AzureAD-Logs will contain the logs for Audit and Sign-In
- Now that the event hubs have been created, the next step is to export data to the Hubs.
Activity Logs
- Go to "Monitor" (left-hand menu) and select "Activity Logs."
- Once on the activity logs page, click "Diagnostics settings."
- Select the subscription that was used for the creation of the Event Hub Name Space and then select "+ Add diagnostic setting".
- Select the required settings for the collection of Activity Logs as displayed in the image below.
- Once the settings are set, click "Save" in the upper left of the screen then go back to the diagnostic settings and confirm the settings are in place.
Sign-In/Audit Logs
- Go to "Azure Active Directory" in the left-hand menu.
- Select "Sign-ins."
- Go to "Export Data Settings" in the top left of the screen.
- Proceed to set the diagnostic settings to reflect the image below.
- Once completed, the log stream for both Audit Logs and Sign-in Logs will be set up.
Required Information
Below is the information AgileBlue requires in order for the collector to be able to connect to the Event Hubs and retrieve data.
- Event Hub Connection String
- This can be found in the Event Hub NameSpace under "Shared Access Policies."
- Then select "RootManageSharedAccessKey" and copy the connection string-primary key, which will be sent back to AgileBlue
- Storage Account
- In order to allow the collector to keep track of the events, a storage account is needed in order to allow write back.
- To create a storage account, go to All Services > Storage > Storage Accounts.
- Then select "Create Storage Account" and use the settings reflected below.
- Click "Review Create".
- Proceed to review the setup storage account and go to "Access Keys".
- Here, you will need to copy the storage account name and the values in key1.
- AgileBlue will also need the event hub names (not the name of the event hub namespace).
- Once these steps are completed and the information has been gathered, send an email to support@agileblue.com to notify our team. A specialist will then send an encrypted email back, to which you can reply with the required information.
Questions? Contact AgileBlue Support.
Email: support@agileblue.com
Phone: (216) 606-9400