Getting Data In

Which add-on for o365 and Azure log collection?

ojay
Path Finder

Hi all,

I am planning on integrating o365 and Azure cloud services to my Splunk on-prem environment.

Now there are several Add-Ons to choose from in Splunkase

  • Microsoft Azure Add on for Splunk
  • Splunk Add-on for Microsoft Office 365
  • Splunk Add-on for Microsoft Cloud Services

What is the main difference between these Add-Ons and which should i use? The documentation did not really help.

"The Splunk Add-on for Microsoft Office 365 replaces the modular input for the Office 365 Management API within the Splunk Add-on for Microsoft Cloud Services."

  • Is it still possible to collect the o365 logs with the Cloud Services add-on which collects via so called event hubs?
  •  

Thank you,

O.

Tags (3)
0 Karma

ojay
Path Finder

In case i use both add-on's do I need to create two seperate application integrations?

0 Karma

ojay
Path Finder

Thank you for the quick feedback, the guide is helpful but i was more looking into a comparison about what add-on to use.

Is the "Splunk Add-on for Microsoft Cloud Services" able to get the O365 data? Is it advised to use it?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

we have used this instructions 

https://www.ciraltos.com/use-splunk-to-collect-logs-from-office-365-and-azure-ad/ to setup M365 data collection and presentation. This guide is little bit outdated, but you could manage configuration with small modifications.
r. Ismo
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...