Trying to figure out which one i need to have visibility of Azure AD security Logs?
https://splunkbase.splunk.com/app/3110/#/details
OR
https://splunkbase.splunk.com/app/4055/#/overview
thanks
We use Splunk Add-on for Microsoft Office 365 and it is able to pull those logs. Just make sure you have an app registration setup with the correct permissions and the client key beforehand.
Pretty simply setup, just define your input then select what logs you want
Andrew
We use Splunk Add-on for Microsoft Office 365 and it is able to pull those logs. Just make sure you have an app registration setup with the correct permissions and the client key beforehand.
Pretty simply setup, just define your input then select what logs you want
Andrew