All Apps and Add-ons

Microsoft Office 365 Reporting Add-on for Splunk: How to limit it to pass on only specific types of events?


We're configuring the o365 reporting add-on, and want to limit it to pass on only specific types of events. I'm not seeing an obvious way to do that, and the docs are limited to installing and connecting it. I could treat it like a regular heavy-forwarder and try to limit events by putting something in an inputs.conf file, but if there's a pre-defined way I'd rather do that.

0 Karma

Splunk Employee
Splunk Employee

What types of events do you want to limit? The add-on uses the Office 365 reporting web service Message Trace Report to collect data. You could modify the Python code used to get the data to add any query parameters you want. Alternatively, you could use props and transforms to do a regex match and drop events you don't want into nullQueue.

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>