Splunk Enterprise

How to configure REST API endpoints to fetch data from Office 365 Admin Centre?

MousumiChowdhur
Contributor

Hi All,

I am trying to configure REST API endpoints to fetch data from office 365 Admin Center. I am trying to do that via Splunk Add-On for Microsoft Office 365. (Please let me know if I am doing it wrong because I don't see any Splunk document that say how to configure REST endpoints to fetch Admin Center data).

So far I have got the tenant created and this is able to access the APIs.

My question is where do I configure the endpoints or what input type and content type should I select on Splunk Add-On for Microsoft Office 365  as I don't see an option to add the endpoints anywhere in the TA? Also, is there any other way to configure this?

Thanks in advance for your help and suggestions!! Apologies for not being able to share any screenshots due to security concerns.

0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...