All Apps and Add-ons

Microsoft Office 365 Reporting Add-on for Splunk: How to limit it to pass on only specific types of events?

duke_splunk_adm
Engager

We're configuring the o365 reporting add-on, and want to limit it to pass on only specific types of events. I'm not seeing an obvious way to do that, and the docs are limited to installing and connecting it. I could treat it like a regular heavy-forwarder and try to limit events by putting something in an inputs.conf file, but if there's a pre-defined way I'd rather do that.

0 Karma

jconger
Splunk Employee
Splunk Employee

What types of events do you want to limit? The add-on uses the Office 365 reporting web service Message Trace Report to collect data. You could modify the Python code used to get the data to add any query parameters you want. Alternatively, you could use props and transforms to do a regex match and drop events you don't want into nullQueue.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...