<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704531#M81252</link>
    <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;I’m working on integrating a Microsoft Office 365 tenant hosted in China (managed by 21Vianet) with Splunk Cloud. I am using the &lt;STRONG&gt;Splunk Add-on for Microsoft Office 365&lt;/STRONG&gt; but need help configuring it specifically for the China tenant.&lt;/P&gt;&lt;P&gt;I understand that the endpoints for China are different from the global Microsoft 365 environment. For instance:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Graph API Endpoint&lt;/STRONG&gt;: &lt;A href="https://microsoftgraph.chinacloudapi.cn" target="_blank" rel="noopener"&gt;https://microsoftgraph.chinacloudapi.cn&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;AAD Authorization Endpoint&lt;/STRONG&gt;: &lt;A href="https://login.partner.microsoftonline.cn" target="_blank" rel="noopener"&gt;https://login.partner.microsoftonline.cn&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could someone provide step-by-step instructions or point me to the necessary configuration files (like inputs.conf) or documentation to correctly set this up for:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Subscription to O365 audit logs&lt;/LI&gt;&lt;LI&gt;Graph API integration&lt;/LI&gt;&lt;LI&gt;Event collection&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, if there are any known challenges or limitations specific to the China tenant setup, I’d appreciate insights on those as well.&lt;/P&gt;&lt;P&gt;Thank you in advance for your guidance!&lt;BR /&gt;&lt;BR /&gt;Tilakram&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 18:07:25 GMT</pubDate>
    <dc:creator>Tilakram</dc:creator>
    <dc:date>2024-11-15T18:07:25Z</dc:date>
    <item>
      <title>Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704531#M81252</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;I’m working on integrating a Microsoft Office 365 tenant hosted in China (managed by 21Vianet) with Splunk Cloud. I am using the &lt;STRONG&gt;Splunk Add-on for Microsoft Office 365&lt;/STRONG&gt; but need help configuring it specifically for the China tenant.&lt;/P&gt;&lt;P&gt;I understand that the endpoints for China are different from the global Microsoft 365 environment. For instance:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Graph API Endpoint&lt;/STRONG&gt;: &lt;A href="https://microsoftgraph.chinacloudapi.cn" target="_blank" rel="noopener"&gt;https://microsoftgraph.chinacloudapi.cn&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;AAD Authorization Endpoint&lt;/STRONG&gt;: &lt;A href="https://login.partner.microsoftonline.cn" target="_blank" rel="noopener"&gt;https://login.partner.microsoftonline.cn&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could someone provide step-by-step instructions or point me to the necessary configuration files (like inputs.conf) or documentation to correctly set this up for:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Subscription to O365 audit logs&lt;/LI&gt;&lt;LI&gt;Graph API integration&lt;/LI&gt;&lt;LI&gt;Event collection&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, if there are any known challenges or limitations specific to the China tenant setup, I’d appreciate insights on those as well.&lt;/P&gt;&lt;P&gt;Thank you in advance for your guidance!&lt;BR /&gt;&lt;BR /&gt;Tilakram&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 18:07:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704531#M81252</guid>
      <dc:creator>Tilakram</dc:creator>
      <dc:date>2024-11-15T18:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704601#M81253</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274078"&gt;@Tilakram&lt;/a&gt;&amp;nbsp;Add-on doesn’t support Azure china ByDefault so i am afraid if it will work or not.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 05:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704601#M81253</guid>
      <dc:creator>Meett</dc:creator>
      <dc:date>2024-11-18T05:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704602#M81254</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271791"&gt;@Meett&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the quick response! I appreciate your insight.&lt;/P&gt;&lt;P&gt;If the Splunk Add-on for Microsoft Office 365 doesn’t natively support Azure China, are there any recommended workarounds or custom configurations (e.g., modifying inputs.conf or using custom scripts) that could enable data collection for China tenants?&lt;/P&gt;&lt;P&gt;Alternatively, are there other Splunk-supported methods or integrations that you’d recommend for ingesting Microsoft Office 365 logs from Azure China tenants? For instance, could a custom API integration with the Graph API endpoint &lt;A href="https://microsoftgraph.chinacloudapi.cn" target="_blank" rel="noopener"&gt;https://microsoftgraph.chinacloudapi.cn&lt;/A&gt; be a feasible approach?&lt;/P&gt;&lt;P&gt;Looking forward to your thoughts!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Tilakram&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 06:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/704602#M81254</guid>
      <dc:creator>Tilakram</dc:creator>
      <dc:date>2024-11-18T06:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/751568#M82212</link>
      <description>&lt;P&gt;Hello, I am having similar issues.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274078"&gt;@Tilakram&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271791"&gt;@Meett&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Were you able to fix it or know if 21V is supported within Splunk for log ingestion?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 14:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/751568#M82212</guid>
      <dc:creator>Moni</dc:creator>
      <dc:date>2025-08-13T14:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/751571#M82213</link>
      <description>&lt;P&gt;Not knowing the app itself I might say that if the Chinese tenants differ _only_ on the service URI, you might try to edit the app yourself and see if changing the URI(s) in the code helps.&lt;/P&gt;&lt;P&gt;The downside is that you'll have to do it again on each app upgrade and your version would be unsupported - in case something doesn't work you're on your own.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 15:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Steps-for-Configuring-Splunk-Add-on-for-Microsoft-Office-365-for/m-p/751571#M82213</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-13T15:06:45Z</dc:date>
    </item>
  </channel>
</rss>

