All Apps and Add-ons

Need help with Splunk Add-on for Microsoft Office 365

SS1
Path Finder

Hi,

We are working on setting up splunk 0365 addon. It looks like our tenant is used by multiple groups/domains, how do we filter to extract only specific group/domain of events to be indexed into splunk. I assume we have to filter out the data in step 2 or 3 from below steps but no idea around o365 side of things

  1. Add the Splunk Add-on for Microsoft Office 365
  2. Turn on Office 365 Audit Logging
  3. Create the Application in Azure AD
  4. Configure the Splunk Add-on for Microsoft Office 365
  5. Verify Logging
  6. Add the Microsoft 365 App for Splunk Add-on

https://docs.splunk.com/Documentation/AddOns/released/MSO365/About

 

 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...