Is there a way to make the SAML Group name be human readable name of the groups as they appear in Azure instead of the Object IDs? So it's easier to understand which Group has access to what Role?
Thank you!
If the mapping between object id and group name is available in other events you have in splunk, you could attempt some sort of "join".
I have a csv file with all the ObjectID mapping. I'm wondering if there is a way to map that so the name can show in the view instead of the Object ID