All Apps and Add-ons

O365 add-on - What is the new o365:graph:api used for? How to connect to O365 graph using add-on

kcooper
Communicator

Looking to see if we can ingest data from O365 that would list a person's name and what they accessed within Sharepoint. 

We were hoping that the new Graph API input from the O365 add-on would get us this information. 

Our O365 admin states that he needs to setup an app registration for us to access O365 Graph. Different than the Tenant ID and Client ID we are using to connect to O365 from the SPlunk add-on

He said - It would need to connect to Graph with the App ID and shared secret at a minimum

What endpoint is Splunk trying to pull from when it is using the Graph API Inputs?

O365 add-on documentation states: 

 

O365:graph:api              All Audit events and reports visable through the Microsoft Graph API endpoints. This

                                              includes all the logs events and reports visable thr the MS graphic API

 
Any help is appreciated. 
0 Karma

kcooper
Communicator

Does anyone have any additional information about the Graph API input in the O365 add-on? 

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...