All Apps and Add-ons

How to load Teams Azure Audit log events into Splunk - Not just the Teams Calling data

SplunkIsFun
Engager

Hi Community,

We have the "Splunk Add-on for Microsoft Office 365" installed.  We've created "Inputs" for "Audit.AzureActiveDirectory", "Audit.Exchange","Audit.SharePoint".

As a result, we are getting all the Azure, Exchange, and SharePoint Azure audit log events loaded into Splunk!

Perfect!

Now we want to add the "Teams" audit log events also.   But we don't see an "Audit.Teams" entry in the "Content Type" picklist on the "Add Management Activity" screen.  We only see the entries listed above.

The only option we see relative to Teams is on the "Create New Input" list and that only loads aggregate Usage Report data on calliong.  Unfortunately, that is useless for us.

Has anyone figured out how to load/ingest all the Teams related Azure Audit Log events like the above AzureAD, Exchange, SharePoint events are loaded?

Thanks in advance for any advice!!

Labels (2)
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...