We want to send Azure Information Protection (AIP) data to Splunk. I have read the Splunk Docs on how to set up the Splunk Add-On for Microsoft Cloud Services to collect data, but it doesn't specify which services within Azure that it can collect data from.
Does anyone know if the add-on can be used to collect from AIP?
I too am I trying to onboard Azure Information Protection (AIP) activity & usage logs into Splunk, but I cannot find any detailed instructions for doing so. None of the responses posted here so far seem to apply to this specific data source. Were you able to find a solution?
Hi @sjcoluccio67 ,
In case you haven't found this, here's the link to the doc detailing the API Calls that the SA for MSCS is referencing:
This doc also links to the MS API definitions.
You can refer this blog:
Also you can use this app:
Let me know if this helps!!