Hi,
We are working on setting up splunk 0365 addon. It looks like our tenant is used by multiple groups/domains, how do we filter to extract only specific group/domain of events to be indexed into splunk. I assume we have to filter out the data in step 2 or 3 from below steps but no idea around o365 side of things
https://docs.splunk.com/Documentation/AddOns/released/MSO365/About