All Apps and Add-ons

O365 add-on - What is the new o365:graph:api used for? How to connect to O365 graph using add-on

kcooper
Communicator

Looking to see if we can ingest data from O365 that would list a person's name and what they accessed within Sharepoint. 

We were hoping that the new Graph API input from the O365 add-on would get us this information. 

Our O365 admin states that he needs to setup an app registration for us to access O365 Graph. Different than the Tenant ID and Client ID we are using to connect to O365 from the SPlunk add-on

He said - It would need to connect to Graph with the App ID and shared secret at a minimum

What endpoint is Splunk trying to pull from when it is using the Graph API Inputs?

O365 add-on documentation states: 

 

O365:graph:api              All Audit events and reports visable through the Microsoft Graph API endpoints. This

                                              includes all the logs events and reports visable thr the MS graphic API

 
Any help is appreciated. 
Labels (1)
0 Karma

kcooper
Communicator

Does anyone have any additional information about the Graph API input in the O365 add-on? 

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...