Splunk Enterprise Security

Splunk Add-on for Microsoft Office 365

macklaud
New Member

Hi,

I receive all the data from different tenants, but my data is not tagged to be able to use it in my Enterprise Security, although I have "Authentication and Change" data models enabled.

I have the "Splunk Add-on application for Microsoft Office 365" installed on an HF and the MSO365 application installed on my search head.
I have a cluster Splunk configuration with three indexers, the TA was copied to the master and also bundeled in the indexers.

Greetings.

0 Karma

macklaud
New Member

I have fixed copying the Ta on my Search Head.
Regards.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...