Hi,
I'm currently using 'Splunk Add-on for Microsoft Office 365' and we are able to see the following sources:
sourcetype for all is 'o365:management:activity'.
I'm looking to gather information about users, groups, devices etc., to use for 'Asset and Identity framework' in Splunk ES. So, I followed the documentation - https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureMicrosoftEntraIDMetadataInp...
Even after doing this, I'm not receiving the expected logs. Has anyone faced similar issue?
I'm thinking of using 'Splunk-add-on-microsoft-azure' app for this because it helps with users, devices, groups information based on the documentation - https://github.com/splunk/splunk-add-on-microsoft-azure/wiki/Create-an-Azure-AD-App-Registration But I see the app (https://splunkbase.splunk.com/app/3757) is not supported. Does anyone use this app? Can we use non supported apps in production?
Thanks!
Technically, yes you can use this app in production.
Unsupported means Splunk doesn’t guarantee updates, bug fixes, or compatibility with future versions.
If there’s no other option, most of us end up using 3rd party apps or add-ons based on what fits our needs.
Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
Can you help me with the first part of question about 'Splunk Add-on for Microsoft Office 365'?
Have you registered this app in Entra side? Without that it cannot access EntraId.
There are instructions in this manual how you should troubleshoot it. Just follow those instructions and tell to us if there are anything in internal logs where you need our help!