<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exchange Online Logs in Splunk in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Exchange-Online-Logs-in-Splunk/m-p/756077#M12777</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to use Splunk to gather email metrics. For example, what email was send, to whom, whether it had an attachment, size of email and/or attachment. Seems like the O365 logs are pretty bad. E.g. The send activity doesn't even capture the recipient. Has anyone had any luck capturing this data? Appreciate any help you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
    <pubDate>Tue, 02 Dec 2025 16:03:12 GMT</pubDate>
    <dc:creator>ringo227</dc:creator>
    <dc:date>2025-12-02T16:03:12Z</dc:date>
    <item>
      <title>Exchange Online Logs in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Exchange-Online-Logs-in-Splunk/m-p/756077#M12777</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to use Splunk to gather email metrics. For example, what email was send, to whom, whether it had an attachment, size of email and/or attachment. Seems like the O365 logs are pretty bad. E.g. The send activity doesn't even capture the recipient. Has anyone had any luck capturing this data? Appreciate any help you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 16:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Exchange-Online-Logs-in-Splunk/m-p/756077#M12777</guid>
      <dc:creator>ringo227</dc:creator>
      <dc:date>2025-12-02T16:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange Online Logs in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Exchange-Online-Logs-in-Splunk/m-p/756181#M12783</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314559"&gt;@ringo227&lt;/a&gt;&amp;nbsp;- Only way currently available on Splunkbase to collect the email logs is with Office 365 Add-on.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureMessageTraceInput/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureMessageTraceInput/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4055" target="_blank"&gt;https://splunkbase.splunk.com/app/4055&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 17:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Exchange-Online-Logs-in-Splunk/m-p/756181#M12783</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-12-04T17:32:22Z</dc:date>
    </item>
  </channel>
</rss>

