Splunk Enterprise Security

Can we use the powershell/ APT for integration of Rights Management Service/ Office 365 (RMS) data to Splunk

MAMAOUI
Explorer

Hi All

I'm looking for informations or methods on integrating RMS (Rights Management service/Office365) into Splunk (Linux).
I'm not sure if we can use the APT (powershell) ....
I checked online - But not able to find any informations.

Thanks

0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

I haven't tested this, but this Microsoft articles states that RMS logs are written to blob storage in W3C extended format:
https://docs.microsoft.com/en-us/information-protection/deploy-use/log-analyze-usage#how-to-access-a...

You should be able to use the blob input in the Splunk Add-on for Microsoft Cloud Services to read this data.

View solution in original post

0 Karma

jconger
Splunk Employee
Splunk Employee

I haven't tested this, but this Microsoft articles states that RMS logs are written to blob storage in W3C extended format:
https://docs.microsoft.com/en-us/information-protection/deploy-use/log-analyze-usage#how-to-access-a...

You should be able to use the blob input in the Splunk Add-on for Microsoft Cloud Services to read this data.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...