Are you using Microsoft O365 Email Add-on for Splunk for these logs?
Try exploring the above package by downloading from splunkbase.
Thank you....I'm guessing this is the only way to do it? Add-on is required? I see it does offer the ability to look at Auth info as well which we are interested in. Thanks for the reply. I'll look into it!! 🙂
Sure, no problem
Happy Splunking