<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Office 365 logs in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520264#M3482</link>
    <description>&lt;P&gt;As I understood at this moment I can use for it universal forwarder too?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 08:06:07 GMT</pubDate>
    <dc:creator>tmardan</dc:creator>
    <dc:date>2020-09-18T08:06:07Z</dc:date>
    <item>
      <title>Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520190#M3476</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;How can I add Office 365 logs to my Splunk if I have 1 search head and 2 indexers and using distributed search?&lt;/P&gt;&lt;P&gt;Should I install all add-ons on 1 indexer and make all configurations on it and all add-ons and app on search head?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 18:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520190#M3476</guid>
      <dc:creator>tmardan</dc:creator>
      <dc:date>2020-09-17T18:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520196#M3477</link>
      <description>&lt;P&gt;I recommend HF.&lt;/P&gt;&lt;P&gt;Indexers are generally overloaded with requests coming from search head.&lt;/P&gt;&lt;P&gt;You can Install on Indexer if they are not overloaded.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 19:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520196#M3477</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-17T19:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520197#M3478</link>
      <description>&lt;P&gt;Thank you for answer!&lt;/P&gt;&lt;P&gt;You mean deploy heavy forwarder on another machine and configure it to receive logs from Office365 and then send them to my indexers?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 19:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520197#M3478</guid>
      <dc:creator>tmardan</dc:creator>
      <dc:date>2020-09-17T19:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520262#M3481</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226194"&gt;@tmardan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;exactly.&amp;nbsp; To separate workloads to different worker machines.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 08:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520262#M3481</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-18T08:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520264#M3482</link>
      <description>&lt;P&gt;As I understood at this moment I can use for it universal forwarder too?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 08:06:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520264#M3482</guid>
      <dc:creator>tmardan</dc:creator>
      <dc:date>2020-09-18T08:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520322#M3485</link>
      <description>&lt;P&gt;Start by reading the docs for the add-ons and apps you plan to install.&amp;nbsp; They should say where they want to be installed.&lt;/P&gt;&lt;P&gt;In general, inputs should not be defined on indexers in a distributed environment.&amp;nbsp; Doing so is likely to cause duplicated data.&amp;nbsp; Put them on a heavy forwarder, instead.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 12:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520322#M3485</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-18T12:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Office 365 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520572#M3496</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226194"&gt;@tmardan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can't use UF as it doesn't have python included in package.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 09:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Office-365-logs/m-p/520572#M3496</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-21T09:02:11Z</dc:date>
    </item>
  </channel>
</rss>

