All Apps and Add-ons

Microsoft Teams Add-on for Splunk on a Cloud IDM


Hi All,

We have an IDM in our cloud environment and we would like to ingest data & logs from Teams with the Add-On installed there, has anyone had any success doing this or is the only way to utilise a Heavy Forwarder?

Labels (1)
0 Karma



Splunk IDM is basically Heavy forwarder running on Linux part of Splunk cloud subscription stack.

If any TA which is compatible to run on Linux Splunk HF then it should ideally work on Splunk IDM. 

I know that Splunk support doesn't support if the TA is not marked to be compatible with Splunk Cloud. But still you could request Splunk support to install on IDM and give a try.  

If this helps, give a like below.
0 Karma


Hi @thambisetty 

I've had it installed on our IDM already and Splunk Support have stated there is no reason it shouldn't work so we have been looking to configure with no luck so far

However I've got a feeling that the issue may lie on our Teams admin side trying to configure the credentials, tokens and certs correctly for "public" access, just trying to ascertain if anyone had any success so far with this setup and what pitfalls were encountered

0 Karma
Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...