All Apps and Add-ons

O365 Audit logging

matthewhasty
Explorer

My company is beginning to use Power BI and we would like to get the audit logs from it into Splunk. I saw in the documentation that this gets audit logs from Exchange Online, SharePoint online and azure ad, but I did not see Power BI in this.

Is power BI included in this (as I saw a requirement for viewing PowerBI logs was having an Echange Online license)? I saw some powershell scripts where Power Bi logs are able to be pulled from unified audit logging, I did not know if this was where the app would pull audit from.

0 Karma
1 Solution

sylbaea
Communicator

Yes Power BI activity audit is included in Office 365 Management API, I do use it already... You can pull those events (along with AD, Exchange, SharePoint, etc.) using one of the below apps:
https://splunkbase.splunk.com/app/3110
https://splunkbase.splunk.com/app/4055

It is part of "General" category documented in:
https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api...

Regards.

View solution in original post

sylbaea
Communicator

Yes Power BI activity audit is included in Office 365 Management API, I do use it already... You can pull those events (along with AD, Exchange, SharePoint, etc.) using one of the below apps:
https://splunkbase.splunk.com/app/3110
https://splunkbase.splunk.com/app/4055

It is part of "General" category documented in:
https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api...

Regards.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...