All Apps and Add-ons

Ingesting Email data using Splunk Add-on for Microsoft Office 365

vishalduttauk
Communicator

Hi there,

 

We have an on prem Exchange mailbox which we monitor via the Exchange logs. We pick out key words from the subject line to trigger alerts.

 

Our mailbox is moving into Exchange online so i've been working with our Azure team and managed to integrate Splunk Enterprise (on prem) with a test online mailbox and so far i am ingesting generic information about the mailbox via the Splunk Add-on for Microsoft Office 365. Information like information like Issue Warning Quota (Byte), Prohibit, Send Quota (Byte) and Prohibit Send/Receive Quota.

The 2 inputs i've created are Message Trace and Mailbox (which ingests the mailbox data above).

What i want to do is to ingest the emails themselves. The key information like subject, the body (if possible), from address and to address. Is this possible using is add on?

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @vishalduttauk 

Have you seen  Microsoft O365 Email Add-on for Splunk? The description of this include "The Microsoft® O365® Email Add-on for Splunk® ingests O365 emails via Microsoft’s Graph API." so I think this might give you the email content that you need!

Check it out and let me know if you need any further help!

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

vishalduttauk
Communicator

I have installed this one but i've not been able to get it working. I'm using the same proxy as with the Splunk Add-on for Microsoft Office 365 and  I've put in an incorrect secret key but i don't get any kind of error like i do with the Splunk Add-on for Microsoft Office 365.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Ah okay, I'm sorry Im not too familiar with the app, but hopefully someone else on here might have experience with it. Have you seen the "Details" tab on https://splunkbase.splunk.com/app/5365 which has some setup instructions?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...