We have a requirement to ingest Office 365 Security & Compliance data into Splunk Cloud. So kindly let us know do we have any Add-on or app to ingest those logs into Splunk Cloud.
If yes, then kindly provide the app or add-on information so that we will configure the same into Splunk Cloud.
And also if you have any document for it then kindly share it.
This will help a bunch:
did you try this add-on Microsoft Graph Security API ? it has nice features for ingest all security alerts.
Can anyone help on my query.
MS Office 365 is configured via Azure portal right?
You can configure the app and add-on
Add on to pull the logs via Microsoft management APIs: https://splunkbase.splunk.com/app/4055/
Please make sure to install the required apps/TAs mentioned in Details section.
Ref Doc for configuring the add-on: https://docs.splunk.com/Documentation/AddOns/released/MSO365/ConfigureappinAzureAD