All Apps and Add-ons

How to ingest data from Tenant Office for Microsoft 365 App for Splunk?

Mimoune06
Engager

Hello,

I am setting up this application (Microsoft 365 App for Splunk https://splunkbase.splunk.com/app/3786/) with our office tenant so that the dashboards work, I have followed the instructions on the documentation but I miss some things on the dashboards of exchange and Defender. I installed the add-on security and set up the inputs, gave the necessary authorizations from an application on Azure but no data passes. Same thing for Exchange, I followed the account creation procedure + rights, still nothing.

Add-on security : https://splunkbase.splunk.com/app/6207/ 
Exchange add-on : https://splunkbase.splunk.com/app/3720/ 

Has anyone had the same problem as me? Or the applications I use are no longer adequate for the Office 365 application?

Thanks in advance for your help.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...