All Apps and Add-ons

Splunk add-on for Microsoft Cloud Services and O365

konstr
Path Finder

I am trying to on board data from Azure AD and O365 to Splunk cloud. I have both the Splunk add-on for Microsoft Cloud services and the Splunk add-on for Microsoft Office 365 installed on the IDM.

I am in the process of configuring the Azure portal but looking at the docs (O365 and MS cloud Services) both point to MS docs (MS O365 and MS cloud Services) and the process described over there is not exactly what is described on the Splunk Docs.

More specifically I am not sure if I need a "redirect URL" as stated in the MS docs and also I am not sure where to find that. It looks like it might be needed for O365 and there was a way to get it through the MS cloud Services add-on however this has since been updated and it's no longer there and O365 data should be forwarded from the O365 add-on which doesn't provide it either.

I managed to write down a few steps for both Azure and O365 configuration on the Azure portal but I am looking for some feedback on if I am understanding everything correctly and if this is al that is needed to be done.

Here are the steps:
alt text

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...