<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting Microsoft Teams Data into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631320#M108207</link>
    <description>&lt;P&gt;Ahh, got it. You have to define 3 different Inputs :&lt;/P&gt;&lt;P&gt;1. Create a Teams Webhook input&lt;/P&gt;&lt;P&gt;2. Create a Teams Subscription input&lt;/P&gt;&lt;P&gt;3. Create a Teams Call Record input&lt;/P&gt;&lt;P&gt;As described in the details of&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4994" target="_blank"&gt;Microsoft Teams Add-on for Splunk | Splunkbase&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Subscription input you can define the Webhook URL.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 13:17:34 GMT</pubDate>
    <dc:creator>PaulPanther</dc:creator>
    <dc:date>2023-02-17T13:17:34Z</dc:date>
    <item>
      <title>Getting Microsoft Teams Data into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631301#M108198</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I`m following &lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/splunking-microsoft-teams-data.html" target="_self"&gt;this&lt;/A&gt; article in an attempt to ingest Teams data into Splunk and I need some help with testing the webhook - can someone confirm what the webhook URL is ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;curl WEBHOOK_ADDRESS -d '{"value": "test"}'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, looking at the documentation for the&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4994" target="_self"&gt;Teams Add-on for Splunk&lt;/A&gt;&amp;nbsp;it states that "the&lt;SPAN&gt;Teams Webhook is not available for Splunk Cloud installations." - has anyone found an alternative solution for Cloud Deployments ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We use Splunk in a hybrid (cloud + on prem) environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631301#M108198</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-21T15:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Microsoft Teams Data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631314#M108201</link>
      <description>&lt;P&gt;You must provide the webhook address that you wanna call from Microsoft Teams. How you do the configuration on Microsoft Teams is described here:&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/office/create-and-add-an-outgoing-webhook-in-teams-8e1a1648-982f-4511-b342-6d8492437207" target="_blank"&gt;Create and add an outgoing webhook in Teams - Microsoft Support&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding Splunk Cloud the documentation recommends Azure Function as an alternative:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Note: The Teams Webhook is not available for Splunk Cloud installations. Consider Azure Functions as an alternative.&lt;/LI-CODE&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4994" target="_blank"&gt;Microsoft Teams Add-on for Splunk | Splunkbase&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 12:47:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631314#M108201</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2023-02-17T12:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Microsoft Teams Data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631316#M108203</link>
      <description>&lt;P&gt;Thanks Paul,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Microsoft Teams Add-on for Spunk includes a Microsoft Teams-specific webhook that I`ve configured, but the documentation (link above) does not include the webhook URL for me to test., which is what I`m after.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 12:57:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631316#M108203</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-17T12:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Microsoft Teams Data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631317#M108204</link>
      <description>&lt;P&gt;Okay, so you've&amp;nbsp; already defined a webhook address that is pointing directly to your data collection node or any&amp;nbsp;&lt;SPAN&gt;load balancer, reverse proxy, or tunnel in front.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Then replace the WEBHOOK_ADDRESS placeholder with your defined webhook address and execute the curl command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The test is successful if your test event is searchable with&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;sourcetype="m365:webhook"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 13:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631317#M108204</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2023-02-17T13:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Microsoft Teams Data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631318#M108205</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;Unfortunately I didn`t get that far - when I created a new input in Splunk - add Teams Webhook, there`s no option to specify the URL, as per the screenshot attached. So I`m not sure where/how the webhook needs to be defined.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 13:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631318#M108205</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-17T13:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Microsoft Teams Data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631320#M108207</link>
      <description>&lt;P&gt;Ahh, got it. You have to define 3 different Inputs :&lt;/P&gt;&lt;P&gt;1. Create a Teams Webhook input&lt;/P&gt;&lt;P&gt;2. Create a Teams Subscription input&lt;/P&gt;&lt;P&gt;3. Create a Teams Call Record input&lt;/P&gt;&lt;P&gt;As described in the details of&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4994" target="_blank"&gt;Microsoft Teams Add-on for Splunk | Splunkbase&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Subscription input you can define the Webhook URL.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 13:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631320#M108207</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2023-02-17T13:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Microsoft Teams Data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631563#M108238</link>
      <description>&lt;P&gt;The following article answered all my questions:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Ingesting-logs-from-Microsoft-Teams/m-p/506702" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Ingesting-logs-from-Microsoft-Teams/m-p/506702&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 11:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-Microsoft-Teams-Data-into-Splunk/m-p/631563#M108238</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-20T11:46:48Z</dc:date>
    </item>
  </channel>
</rss>

