Hello,
We are interested in monitoring our O365 and Azure environments using Splunk. There is a TA out available to collect the data but I didn't see a corresponding APP to install on my search heads to view the incoming data. Any suggestions for an app to use or a suite of apps to use for monitoring those events?
Does the Splunk App for Windows Infrastructure handle information from Microsoft Cloud data sources?
Thank you,
Ken
Those add-ons actually include a bunch of prebuilt panels. So while the data may be reused in other apps, you could rock and roll with just the add-ons prebuilt panels if you desire.
Related: What are the Splunk apps and add-ons for Microsoft technologies, and what do I use them for?
I don't think that the Splunk App for Windows Infrastructure will handle these events. The data coming from the TA for MS Cloud Services in JSON.
There are a couple of dashboards, which I think are actually for ES.