Looking to see if we can ingest data from O365 that would list a person's name and what they accessed within Sharepoint.
We were hoping that the new Graph API input from the O365 add-on would get us this information.
Our O365 admin states that he needs to setup an app registration for us to access O365 Graph. Different than the Tenant ID and Client ID we are using to connect to O365 from the SPlunk add-on
He said - It would need to connect to Graph with the App ID and shared secret at a minimum
What endpoint is Splunk trying to pull from when it is using the Graph API Inputs?
O365 add-on documentation states:
O365:graph:api All Audit events and reports visable through the Microsoft Graph API endpoints. This
includes all the logs events and reports visable thr the MS graphic API
Does anyone have any additional information about the Graph API input in the O365 add-on?