All Apps and Add-ons

How to get data from Office365 into Splunk

rjj
New Member

I have the Trial version of Splunk with the Microsoft 365 App. How do I link Office 365 with Splunk.

0 Karma

adnauseam
Explorer

As others have said, you do need the Splunk Add-On for Microsoft Office 365 to onboard the data, but if you already have the M365 App for Splunk installed, it has a really helpful visual setup guide that walks you through the whole process of on-boarding O365, from Azure App registration to configuring the O365 Add-On.

0 Karma

jconger
Splunk Employee
Splunk Employee

Splunk apps typically visualize data, while Splunk add-on typically gather data. The M365 app relies on the Splunk Add-on for Microsoft Office 365 to gather the necessary data.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In addition to the app, you also need an add-on for MS365 (add-ons collect data that apps display). There are several add-ons available on splunkbase. The documentation for them should explain what you need to do both in Splunk and in 365 to get data into Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...