All Apps and Add-ons

O365 add-on - What is the new o365:graph:api used for? How to connect to O365 graph using add-on

kcooper
Communicator

Looking to see if we can ingest data from O365 that would list a person's name and what they accessed within Sharepoint. 

We were hoping that the new Graph API input from the O365 add-on would get us this information. 

Our O365 admin states that he needs to setup an app registration for us to access O365 Graph. Different than the Tenant ID and Client ID we are using to connect to O365 from the SPlunk add-on

He said - It would need to connect to Graph with the App ID and shared secret at a minimum

What endpoint is Splunk trying to pull from when it is using the Graph API Inputs?

O365 add-on documentation states: 

 

O365:graph:api              All Audit events and reports visable through the Microsoft Graph API endpoints. This

                                              includes all the logs events and reports visable thr the MS graphic API

 
Any help is appreciated. 
Labels (1)
0 Karma

kcooper
Communicator

Does anyone have any additional information about the Graph API input in the O365 add-on? 

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...