All Apps and Add-ons

Difference with Splunk Add-on for Microsoft Cloud Services

sylbaea
Communicator

Hello,

I just saw the release of Splunk Add-on for Microsoft Office 365. What is the difference with Splunk Add-on for Microsoft Cloud Services. I used to have this one in my environment and does not understand the purpose of the new one ?

1 Solution

jconger
Splunk Employee
Splunk Employee

In short, the Office 365 input in the Splunk Add-on for Microsoft Cloud Services has migrated to its own add-on (the Splunk Add-on for Microsoft Office 365):

  • The Splunk Add-on for Microsoft Cloud Services has an Office 365 Management Activity API input.
  • The Splunk Add-on for Microsoft Office 365 supersedes the MSCS O365 input. There are some improvements too. Check out the migration and new feature section in the docs -> http://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes#Migration
  • Both of the above add-ons focus on activity and operation.
  • The Microsoft Office 365 Reporting Add-on gathers email message trace data (sender, receiver, status, subject line, etc.) The add-on uses the MessageTrace report via the O365 reporting web service. There are multiple reports available via this web service (thus the generic name of the add-on) -> https://msdn.microsoft.com/en-us/library/office/jj984325.aspx#Anchor_4

View solution in original post

dbaldwin_splunk
Splunk Employee
Splunk Employee

Splunk Add-on for Microsoft Office 365 replaces Office 365 modular input within Splunk Add-on for Microsoft Cloud Services. Customers who wish to pull Office 365 management activity events are recommended to disable Office 365 modular input within Splunk Add-on for Microsoft Cloud Services add-on and use Splunk Add-on for Microsoft Office 365 instead.

Note that source types have changed in Splunk Add-on for Microsoft Office 365 and any panels, dashboards, spl, etc will need to be adjusted.

Office 365 modular input is planned to be deprecated in a future release of Splunk Add-on for Microsoft Cloud Services add-on.

sylbaea
Communicator

Thanks a lot for clarification

0 Karma

jconger
Splunk Employee
Splunk Employee

In short, the Office 365 input in the Splunk Add-on for Microsoft Cloud Services has migrated to its own add-on (the Splunk Add-on for Microsoft Office 365):

  • The Splunk Add-on for Microsoft Cloud Services has an Office 365 Management Activity API input.
  • The Splunk Add-on for Microsoft Office 365 supersedes the MSCS O365 input. There are some improvements too. Check out the migration and new feature section in the docs -> http://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes#Migration
  • Both of the above add-ons focus on activity and operation.
  • The Microsoft Office 365 Reporting Add-on gathers email message trace data (sender, receiver, status, subject line, etc.) The add-on uses the MessageTrace report via the O365 reporting web service. There are multiple reports available via this web service (thus the generic name of the add-on) -> https://msdn.microsoft.com/en-us/library/office/jj984325.aspx#Anchor_4

jaxjohnny2000
Builder

The Splunk Add-on for Microsoft Cloud Services documentation still shows the sourcetype ms:o365:management.  

https://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Sourcetypes

0 Karma

kevinmanson
Explorer

Jason,
Can you also expand on the this new app vs Microsoft Azure Active Directory Reporting Add-on for Splunk https://splunkbase.splunk.com/app/3757/

0 Karma

sylbaea
Communicator

Thanks a lot for clarification and very detailed answer

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...