Hello guys,
I need to collect logs when the "admin of azure" reset password or exclude one account.
I have tried use Splunk Add-on for Microsoft Azure OR Splunk Add-on for Microsoft O365 but I cant received this logs. I received the microsoft substrate management.
Is there any orther app to install to collect this ?
This one have always help with all Azure onboarding questions, want to give it a try? - https://jasonconger.com/splunk-azure-gdi/
Reference - https://www.splunk.com/en_us/blog/tips-and-tricks/getting-microsoft-azure-data-into-splunk.html?loca...