Hi
I am trying to create alerts and dashboards for my o365 and AD logs.
Is there somewhere that has an overview of the different options in for example Operations? Since I dont have a log from when a user is created, I dont know the value the log will say eg, UserCreated, UserWasCreated, CreateUser.
Hope it makes sense
Hi @NJ,
did you already explored, in splunkbase some apps as: Microsoft 365 App for Splunk (https://splunkbase.splunk.com/app/3786)?
Ciao.
Giuseppe
Yes and that helped but want to know all the possible values under for example the Operation field that 365 and AD logs can produce.
Hi @NJ,
sorry but I think that this isn't the best locatiopn for this answer, this is a Microsoft knowldege not a Splunk knowledge!
Ciao.
Giuseppe