All Apps and Add-ons

Microsoft Office 365 Reporting Add-on for Splunk: How to limit it to pass on only specific types of events?

duke_splunk_adm
Engager

We're configuring the o365 reporting add-on, and want to limit it to pass on only specific types of events. I'm not seeing an obvious way to do that, and the docs are limited to installing and connecting it. I could treat it like a regular heavy-forwarder and try to limit events by putting something in an inputs.conf file, but if there's a pre-defined way I'd rather do that.

0 Karma

jconger
Splunk Employee
Splunk Employee

What types of events do you want to limit? The add-on uses the Office 365 reporting web service Message Trace Report to collect data. You could modify the Python code used to get the data to add any query parameters you want. Alternatively, you could use props and transforms to do a regex match and drop events you don't want into nullQueue.

0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...