All Apps and Add-ons

Need help with Splunk Add-on for Microsoft Office 365

SS1
Path Finder

Hi,

We are working on setting up splunk 0365 addon. It looks like our tenant is used by multiple groups/domains, how do we filter to extract only specific group/domain of events to be indexed into splunk. I assume we have to filter out the data in step 2 or 3 from below steps but no idea around o365 side of things

  1. Add the Splunk Add-on for Microsoft Office 365
  2. Turn on Office 365 Audit Logging
  3. Create the Application in Azure AD
  4. Configure the Splunk Add-on for Microsoft Office 365
  5. Verify Logging
  6. Add the Microsoft 365 App for Splunk Add-on

https://docs.splunk.com/Documentation/AddOns/released/MSO365/About

 

 

0 Karma
Get Updates on the Splunk Community!

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...