All Apps and Add-ons

How to ingest data from Tenant Office for Microsoft 365 App for Splunk?

Mimoune06
Engager

Hello,

I am setting up this application (Microsoft 365 App for Splunk https://splunkbase.splunk.com/app/3786/) with our office tenant so that the dashboards work, I have followed the instructions on the documentation but I miss some things on the dashboards of exchange and Defender. I installed the add-on security and set up the inputs, gave the necessary authorizations from an application on Azure but no data passes. Same thing for Exchange, I followed the account creation procedure + rights, still nothing.

Add-on security : https://splunkbase.splunk.com/app/6207/ 
Exchange add-on : https://splunkbase.splunk.com/app/3720/ 

Has anyone had the same problem as me? Or the applications I use are no longer adequate for the Office 365 application?

Thanks in advance for your help.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...