Splunk Search

o365 admin center workload

weetabixsplunk
Explorer

Hi guys,

I'm trying to create a search that triggers an alert every time a user has been signed out of their o365 session, however, I am unable to identify which is the correct workload.

I'd like to clarify that I currently do not have access to the o365 splunk add-on (and it probably won't be installed anytime soon). Which workload do I need to use if I need to identify activity performed in the o365 admin portal?

I initially thought it would be index=o365 sourcetype=o365:management:activity Workload=SecurityComplianceCenter but it doesn't seem to show me anything related to sessions that have been signed out.

Any useful feedback would be much appreciated.

 

Thanks!

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...