All Apps and Add-ons

Not getting Entra ID logs - Splunk Add-on for Microsoft Office 365

splunker2k24
New Member

Hi,

I'm currently using 'Splunk Add-on for Microsoft Office 365' and we are able to see the following sources:

  1. audit_exchange
  2. audit_sharepoint
  3. audit_general
  4. audit_azureactivedirectory

sourcetype for all is 'o365:management:activity'.

I'm looking to gather information about users, groups, devices etc., to use for 'Asset and Identity framework' in Splunk ES. So, I followed the documentation - https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureMicrosoftEntraIDMetadataInp...

Even after doing this, I'm not receiving the expected logs. Has anyone faced similar issue?

 

I'm thinking of using 'Splunk-add-on-microsoft-azure' app for this because it helps with users, devices, groups information based on the documentation - https://github.com/splunk/splunk-add-on-microsoft-azure/wiki/Create-an-Azure-AD-App-Registration But I see the app (https://splunkbase.splunk.com/app/3757) is not supported. Does anyone use this app? Can we use non supported apps in production?

Thanks!

0 Karma

PrewinThomas
Motivator

@splunker2k24 

Technically, yes you can use this app in production.

Unsupported means Splunk doesn’t guarantee updates, bug fixes, or compatibility with future versions.
If there’s no other option, most of us end up using 3rd party apps or add-ons based on what fits our needs.


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

splunker2k24
New Member

Can you help me with the first part of question about 'Splunk Add-on for Microsoft Office 365'?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you registered this app in Entra side? Without that it cannot access EntraId.

There are instructions in this manual how you should troubleshoot it. Just follow those instructions and tell to us if there are anything in internal logs where you need our help!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...