All Apps and Add-ons

Difference with Splunk Add-on for Microsoft Cloud Services

sylbaea
Communicator

Hello,

I just saw the release of Splunk Add-on for Microsoft Office 365. What is the difference with Splunk Add-on for Microsoft Cloud Services. I used to have this one in my environment and does not understand the purpose of the new one ?

1 Solution

jconger
Splunk Employee
Splunk Employee

In short, the Office 365 input in the Splunk Add-on for Microsoft Cloud Services has migrated to its own add-on (the Splunk Add-on for Microsoft Office 365):

  • The Splunk Add-on for Microsoft Cloud Services has an Office 365 Management Activity API input.
  • The Splunk Add-on for Microsoft Office 365 supersedes the MSCS O365 input. There are some improvements too. Check out the migration and new feature section in the docs -> http://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes#Migration
  • Both of the above add-ons focus on activity and operation.
  • The Microsoft Office 365 Reporting Add-on gathers email message trace data (sender, receiver, status, subject line, etc.) The add-on uses the MessageTrace report via the O365 reporting web service. There are multiple reports available via this web service (thus the generic name of the add-on) -> https://msdn.microsoft.com/en-us/library/office/jj984325.aspx#Anchor_4

View solution in original post

dbaldwin_splunk
Splunk Employee
Splunk Employee

Splunk Add-on for Microsoft Office 365 replaces Office 365 modular input within Splunk Add-on for Microsoft Cloud Services. Customers who wish to pull Office 365 management activity events are recommended to disable Office 365 modular input within Splunk Add-on for Microsoft Cloud Services add-on and use Splunk Add-on for Microsoft Office 365 instead.

Note that source types have changed in Splunk Add-on for Microsoft Office 365 and any panels, dashboards, spl, etc will need to be adjusted.

Office 365 modular input is planned to be deprecated in a future release of Splunk Add-on for Microsoft Cloud Services add-on.

sylbaea
Communicator

Thanks a lot for clarification

0 Karma

jconger
Splunk Employee
Splunk Employee

In short, the Office 365 input in the Splunk Add-on for Microsoft Cloud Services has migrated to its own add-on (the Splunk Add-on for Microsoft Office 365):

  • The Splunk Add-on for Microsoft Cloud Services has an Office 365 Management Activity API input.
  • The Splunk Add-on for Microsoft Office 365 supersedes the MSCS O365 input. There are some improvements too. Check out the migration and new feature section in the docs -> http://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes#Migration
  • Both of the above add-ons focus on activity and operation.
  • The Microsoft Office 365 Reporting Add-on gathers email message trace data (sender, receiver, status, subject line, etc.) The add-on uses the MessageTrace report via the O365 reporting web service. There are multiple reports available via this web service (thus the generic name of the add-on) -> https://msdn.microsoft.com/en-us/library/office/jj984325.aspx#Anchor_4

jaxjohnny2000
Builder

The Splunk Add-on for Microsoft Cloud Services documentation still shows the sourcetype ms:o365:management.  

https://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Sourcetypes

0 Karma

kevinmanson
Explorer

Jason,
Can you also expand on the this new app vs Microsoft Azure Active Directory Reporting Add-on for Splunk https://splunkbase.splunk.com/app/3757/

0 Karma

sylbaea
Communicator

Thanks a lot for clarification and very detailed answer

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...