Splunk Enterprise Security

Add-ons for microsoft products

Amire22
Explorer

I would appreciate help from anyone who has encountered a similar problem:

We are using Microsoft's E5 licensing with the following products:

  • Intune
  • Entra ID
  • Defender for endpoint
  • office 365
  • teams

All events from Microsoft are streamed to EventHub and from there to our Splunk ES

We are very confused and don't know which Add-Ons we should install.

I would love to hear from anyone who uses these technologies.

Splunk Enterprise Security

Labels (1)
0 Karma
1 Solution

kiran_panchavat
SplunkTrust
SplunkTrust

@Amire22 

Hello, you can install the Splunk Add-on for Microsoft Cloud Services add-on to onboard the logs to Splunk.  https://splunkbase.splunk.com/app/3110 

https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub... 

https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/ 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

View solution in original post

0 Karma

Amire22
Explorer

thank you

it will include logs from all my products above?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Not necessarily.

There are separate addons for specific services (separate one for Teams, another for Security (Defender and Defender for endpoint) and so on). This one will cover getting data from Event Hub but you might need another addon to parse your data properly and map fields to CIM.

I'm not sure though if the fact that you're pushing the data through Event Hub won't mangle the events since some of those addons expect the inputs to run differently (Graph API?).

You need to go to Splunkbase, type in "microsoft" and check it out

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@Amire22 

Hello, you can install the Splunk Add-on for Microsoft Cloud Services add-on to onboard the logs to Splunk.  https://splunkbase.splunk.com/app/3110 

https://lantern.splunk.com/Data_Descriptors/Microsoft/Getting_started_with_Microsoft_Azure_Event_Hub... 

https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/ 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...