<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add-ons for microsoft products in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750144#M12595</link>
    <description>&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;it will include logs from all my products above?&lt;/P&gt;</description>
    <pubDate>Sun, 20 Jul 2025 13:12:07 GMT</pubDate>
    <dc:creator>Amire22</dc:creator>
    <dc:date>2025-07-20T13:12:07Z</dc:date>
    <item>
      <title>Add-ons for microsoft products</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750139#M12593</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I would appreciate help from anyone who has encountered a similar problem: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;We are using Microsoft's E5 licensing with the following products: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Entra ID&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Defender for endpoint&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;office 365&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;teams&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;All events from Microsoft are streamed to EventHub and from there to our Splunk ES&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;We are very confused and don't know which Add-Ons we should install.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I would love to hear from anyone who uses these technologies.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;LI-PRODUCT title="Splunk Enterprise Security" id="263"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 08:30:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750139#M12593</guid>
      <dc:creator>Amire22</dc:creator>
      <dc:date>2025-07-20T08:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Add-ons for microsoft products</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750142#M12594</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310535"&gt;@Amire22&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello, you can install the&amp;nbsp;Splunk Add-on for Microsoft Cloud Services add-on to onboard the logs to Splunk.&amp;nbsp;&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3110" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3110&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub_data" target="_blank"&gt;https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub_data&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/" target="_blank" rel="noopener"&gt;https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 12:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750142#M12594</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-07-20T12:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Add-ons for microsoft products</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750144#M12595</link>
      <description>&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;it will include logs from all my products above?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 13:12:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750144#M12595</guid>
      <dc:creator>Amire22</dc:creator>
      <dc:date>2025-07-20T13:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Add-ons for microsoft products</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750152#M12596</link>
      <description>&lt;P&gt;Not necessarily.&lt;/P&gt;&lt;P&gt;There are separate addons for specific services (separate one for Teams, another for Security (Defender and Defender for endpoint) and so on). This one will cover getting data from Event Hub but you might need another addon to parse your data properly and map fields to CIM.&lt;/P&gt;&lt;P&gt;I'm not sure though if the fact that you're pushing the data through Event Hub won't mangle the events since some of those addons expect the inputs to run differently (Graph API?).&lt;/P&gt;&lt;P&gt;You need to go to Splunkbase, type in "microsoft" and check it out&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 18:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-ons-for-microsoft-products/m-p/750152#M12596</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-20T18:00:09Z</dc:date>
    </item>
  </channel>
</rss>

