Splunk Search

o365 admin center workload

weetabixsplunk
Explorer

Hi guys,

I'm trying to create a search that triggers an alert every time a user has been signed out of their o365 session, however, I am unable to identify which is the correct workload.

I'd like to clarify that I currently do not have access to the o365 splunk add-on (and it probably won't be installed anytime soon). Which workload do I need to use if I need to identify activity performed in the o365 admin portal?

I initially thought it would be index=o365 sourcetype=o365:management:activity Workload=SecurityComplianceCenter but it doesn't seem to show me anything related to sessions that have been signed out.

Any useful feedback would be much appreciated.

 

Thanks!

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...