Splunk Search

How do you use Splunk to search within document text of wiki server and SharePoint data sources?

roseneric4
Engager

Is it possible to use Splunk as search engine that uses a wiki server and SharePoint as its data sources? It must search within document text for example the contents of the files in a SharePoint document library.

The idea is to create a dashboard with a nice simple search interface that brings back the "articles" highlighting the key term and filtering down based on certain functional or application name etc.

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Splunk does not have a web-crawler component, you would need to fetch all the documents from SharePoint through some means.

Unfortunately, the Splunk Add-on for Microsoft Office 365 only fetches the audit logs for SharePoint, not the actual data. There may be some way to use the Splunk Add-on for Microsoft Cloud Services to fetch the data from Azure Storage Tables, but I am not 100% certain if SharePoint data is accessible via that means.

It seems like the 'official' way is to use one of the methods described at https://docs.microsoft.com/en-us/sharepoint/dev/sp-add-ins/sharepoint-net-server-csom-jsom-and-rest-... to fetch the data, most likely the REST API. You would need to write a script to do the following:

This page probably describes the details of what you'll need to develop.
https://docs.microsoft.com/en-us/sharepoint/dev/sp-add-ins/get-to-know-the-sharepoint-rest-service

Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...