<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What does &amp;quot;notracking@example.com&amp;quot; mean in Splunk Add-on for Microsoft Cloud Services? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432455#M53070</link>
    <description>&lt;P&gt;Hi, all&lt;BR /&gt;
I am currently collecting the ThreatIntelligence Workload using the Splunk Add-on for Microsoft Cloud Services.&lt;/P&gt;

&lt;P&gt;While reviewing the collected logs, I saw a log that the UserId field is "&lt;STRONG&gt;&lt;A href="mailto:notracking@example.com"&gt;notracking@example.com&lt;/A&gt;&lt;/STRONG&gt;", but I do not know what it means.&lt;BR /&gt;
I want to make sure that "&lt;STRONG&gt;&lt;A href="mailto:notracking@example.com"&gt;notracking@example.com&lt;/A&gt;&lt;/STRONG&gt;" is provided by Office 365, or information generated by add-on.&lt;/P&gt;

&lt;P&gt;The RecordType for that log is 41.&lt;/P&gt;

&lt;P&gt;Office 365 Management Schema documents do not provide this information.&lt;/P&gt;

&lt;P&gt;{   [-] &lt;BR /&gt;
     AppName:    Mail&lt;BR /&gt;&lt;BR /&gt;
     AppVersion:     0.0.0000&lt;BR /&gt;&lt;BR /&gt;
     CreationTime:   2019-01-28T22:37:20&lt;BR /&gt;&lt;BR /&gt;
     Id:     #blind#&lt;BR /&gt;&lt;BR /&gt;
     OS:     Win32&lt;BR /&gt;&lt;BR /&gt;
     Operation:  TIUrlClickData &lt;BR /&gt;
     OrganizationId:    #blind# &lt;BR /&gt;
     RecordType:     41 &lt;BR /&gt;
     SourceId:   #blind#&lt;BR /&gt;&lt;BR /&gt;
     SourceWorkload:     Mailflow&lt;BR /&gt;&lt;BR /&gt;
     TimeOfClick:    2019-01-28T22:34:40&lt;BR /&gt;&lt;BR /&gt;
     Url:    &lt;A href="http://abcde.com/?61o1EX=IGCQlSQRYNiGBrD0ALmQHT3LUw"&gt;http://abcde.com/?61o1EX=IGCQlSQRYNiGBrD0ALmQHT3LUw&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;
     UrlClickAction:     2&lt;BR /&gt;&lt;BR /&gt;
     &lt;STRONG&gt;UserId:   &lt;A href="mailto:notracking@example.com"&gt;notracking@example.com&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
     UserIp:     10.10.10.10&lt;BR /&gt;&lt;BR /&gt;
     UserKey:    ThreatIntel&lt;BR /&gt;&lt;BR /&gt;
     UserType:   4&lt;BR /&gt;&lt;BR /&gt;
     Version:    1&lt;BR /&gt;&lt;BR /&gt;
     Workload:   ThreatIntelligence &lt;BR /&gt;
}&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jan 2019 06:11:58 GMT</pubDate>
    <dc:creator>ssanplunk</dc:creator>
    <dc:date>2019-01-30T06:11:58Z</dc:date>
    <item>
      <title>What does "notracking@example.com" mean in Splunk Add-on for Microsoft Cloud Services?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432455#M53070</link>
      <description>&lt;P&gt;Hi, all&lt;BR /&gt;
I am currently collecting the ThreatIntelligence Workload using the Splunk Add-on for Microsoft Cloud Services.&lt;/P&gt;

&lt;P&gt;While reviewing the collected logs, I saw a log that the UserId field is "&lt;STRONG&gt;&lt;A href="mailto:notracking@example.com"&gt;notracking@example.com&lt;/A&gt;&lt;/STRONG&gt;", but I do not know what it means.&lt;BR /&gt;
I want to make sure that "&lt;STRONG&gt;&lt;A href="mailto:notracking@example.com"&gt;notracking@example.com&lt;/A&gt;&lt;/STRONG&gt;" is provided by Office 365, or information generated by add-on.&lt;/P&gt;

&lt;P&gt;The RecordType for that log is 41.&lt;/P&gt;

&lt;P&gt;Office 365 Management Schema documents do not provide this information.&lt;/P&gt;

&lt;P&gt;{   [-] &lt;BR /&gt;
     AppName:    Mail&lt;BR /&gt;&lt;BR /&gt;
     AppVersion:     0.0.0000&lt;BR /&gt;&lt;BR /&gt;
     CreationTime:   2019-01-28T22:37:20&lt;BR /&gt;&lt;BR /&gt;
     Id:     #blind#&lt;BR /&gt;&lt;BR /&gt;
     OS:     Win32&lt;BR /&gt;&lt;BR /&gt;
     Operation:  TIUrlClickData &lt;BR /&gt;
     OrganizationId:    #blind# &lt;BR /&gt;
     RecordType:     41 &lt;BR /&gt;
     SourceId:   #blind#&lt;BR /&gt;&lt;BR /&gt;
     SourceWorkload:     Mailflow&lt;BR /&gt;&lt;BR /&gt;
     TimeOfClick:    2019-01-28T22:34:40&lt;BR /&gt;&lt;BR /&gt;
     Url:    &lt;A href="http://abcde.com/?61o1EX=IGCQlSQRYNiGBrD0ALmQHT3LUw"&gt;http://abcde.com/?61o1EX=IGCQlSQRYNiGBrD0ALmQHT3LUw&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;
     UrlClickAction:     2&lt;BR /&gt;&lt;BR /&gt;
     &lt;STRONG&gt;UserId:   &lt;A href="mailto:notracking@example.com"&gt;notracking@example.com&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
     UserIp:     10.10.10.10&lt;BR /&gt;&lt;BR /&gt;
     UserKey:    ThreatIntel&lt;BR /&gt;&lt;BR /&gt;
     UserType:   4&lt;BR /&gt;&lt;BR /&gt;
     Version:    1&lt;BR /&gt;&lt;BR /&gt;
     Workload:   ThreatIntelligence &lt;BR /&gt;
}&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 06:11:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432455#M53070</guid>
      <dc:creator>ssanplunk</dc:creator>
      <dc:date>2019-01-30T06:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: What does "notracking@example.com" mean in Splunk Add-on for Microsoft Cloud Services?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432456#M53071</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;I have used this add-on as far as I know &lt;CODE&gt;UserId&lt;/CODE&gt; is not created by this add-on. It is created by O365 management activity schema.&lt;BR /&gt;
and it means&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;The UPN (User Principal Name) of the user who performed the action (specified in the Operation property) that resulted in the record being logged; for example, &lt;A href="mailto:my_name@my_domain_name" target="_blank"&gt;my_name@my_domain_name&lt;/A&gt;. Note that records for activity performed by system accounts (such as SHAREPOINT\system or NT AUTHORITY\SYSTEM) are also included.&lt;BR /&gt;
have  a look at this doc for more info:&lt;BR /&gt;
&lt;A href="https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema" target="_blank"&gt;https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432456#M53071</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2020-09-29T23:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: What does "notracking@example.com" mean in Splunk Add-on for Microsoft Cloud Services?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432457#M53072</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Thank you for your help.&lt;BR /&gt;
I checked more information in doc!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 01:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-does-quot-notracking-example-com-quot-mean-in-Splunk-Add-on/m-p/432457#M53072</guid>
      <dc:creator>ssanplunk</dc:creator>
      <dc:date>2019-02-01T01:41:19Z</dc:date>
    </item>
  </channel>
</rss>

