Hi Community,
We have the "Splunk Add-on for Microsoft Office 365" installed. We've created "Inputs" for "Audit.AzureActiveDirectory", "Audit.Exchange","Audit.SharePoint".
As a result, we are getting all the Azure, Exchange, and SharePoint Azure audit log events loaded into Splunk!
Perfect!
Now we want to add the "Teams" audit log events also. But we don't see an "Audit.Teams" entry in the "Content Type" picklist on the "Add Management Activity" screen. We only see the entries listed above.
The only option we see relative to Teams is on the "Create New Input" list and that only loads aggregate Usage Report data on calliong. Unfortunately, that is useless for us.
Has anyone figured out how to load/ingest all the Teams related Azure Audit Log events like the above AzureAD, Exchange, SharePoint events are loaded?
Thanks in advance for any advice!!