Which Splunk Technical Application for Microsoft will pull the TLS details for email/Exchange? Need to be able to report on TLS verdict details (accepted/blocked).
@VatsalJagani will check that route out then. Appreciate the direction.
@donaldwayne1976 - Ideally it should be part of message trace data.
https://splunkbase.splunk.com/app/4055 (Office 365 Add-on) has input for Message Trace data. (Though I'm not sure if that has what you need, but that might be your best bet)
If this does not work, you can build a custom App to fetch the data you need as far as Microsoft provides necessary API to get the data you need.
I hope this helps!!!