All Apps and Add-ons

Not getting Entra ID logs - Splunk Add-on for Microsoft Office 365

splunker2k24
New Member

Hi,

I'm currently using 'Splunk Add-on for Microsoft Office 365' and we are able to see the following sources:

  1. audit_exchange
  2. audit_sharepoint
  3. audit_general
  4. audit_azureactivedirectory

sourcetype for all is 'o365:management:activity'.

I'm looking to gather information about users, groups, devices etc., to use for 'Asset and Identity framework' in Splunk ES. So, I followed the documentation - https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureMicrosoftEntraIDMetadataInp...

Even after doing this, I'm not receiving the expected logs. Has anyone faced similar issue?

 

I'm thinking of using 'Splunk-add-on-microsoft-azure' app for this because it helps with users, devices, groups information based on the documentation - https://github.com/splunk/splunk-add-on-microsoft-azure/wiki/Create-an-Azure-AD-App-Registration But I see the app (https://splunkbase.splunk.com/app/3757) is not supported. Does anyone use this app? Can we use non supported apps in production?

Thanks!

0 Karma

PrewinThomas
Builder

@splunker2k24 

Technically, yes you can use this app in production.

Unsupported means Splunk doesn’t guarantee updates, bug fixes, or compatibility with future versions.
If there’s no other option, most of us end up using 3rd party apps or add-ons based on what fits our needs.


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

splunker2k24
New Member

Can you help me with the first part of question about 'Splunk Add-on for Microsoft Office 365'?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you registered this app in Entra side? Without that it cannot access EntraId.

There are instructions in this manual how you should troubleshoot it. Just follow those instructions and tell to us if there are anything in internal logs where you need our help!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...