Hi,
I need to look at the raw events coming in from Office 365- which is JSON formatted,
and then route them based upon thecontent.
I want to route them based upon the "Workload" field t...
Hello,
I want to use ITSI ContentPack as a base for implementing ITSI. I also see a documentation about it in https://docs.splunk.com/Documentation/ITSICP/current/Config/About
But, it does not t...
...apabilities.The alerts are logged in Microsoft Purview, (a.k.a. the Compliance Center), in Microsoft Defender for Cloud Apps, Microsoft365 Defender and Splunk.My problem is how do we get the necessary data out o...
Hi,
we would like to monitor authentication attempts in our SMTP server (Exchange 2016) but I could not find a way to do so.
We already have IT Essentials with the Exchange ContentPack but S...
...ogs; /opt/splunk/var/log/splunk/splunk_ta_o365_management_activity_Audit_AD.log
O365PortalError: 400:{"error":{"code":"AF20055","message":"Date range for requested content is invalid startTime:2...
Hi, after the installation of ITE Works 4.9.2 and the exchange contentpack. I checked all the dashboards to be sure the data was correctly processed and I realized that some panels were blank. O...
Hi, recently we deployed IT Essential Works with latest Exchange ContentPack. we also deployed the three addons forthe Exchange in the exchange nodes (including IIS and OWA logs). N...
Hi, I have configured IT Essential Works (4.9.2) with Exchange contentpack (1.4.3) and TA-Exchange-ClientAccess (4.0.3). By chance I was checking PowerShell event logs in our exchange s...
I'm using the Splunk Add-on forMicrosoft Cloud Services to ingest logs from Office 365. Specifically, I'm getting the Exchange Online Audit and Azure AD Audit logs.
After the O365 Management A...
We are currently using the Splunk Add-on forMicrosoft Cloud Services but it doesn't support importing of message tracking logs. These logs are critical to our SOC so we need to find a way to e...