All Apps and Add-ons

Steps for Configuring Splunk Add-on for Microsoft Office 365 for China Tenant

Tilakram
New Member

Hello Splunkers,

I’m working on integrating a Microsoft Office 365 tenant hosted in China (managed by 21Vianet) with Splunk Cloud. I am using the Splunk Add-on for Microsoft Office 365 but need help configuring it specifically for the China tenant.

I understand that the endpoints for China are different from the global Microsoft 365 environment. For instance:

Could someone provide step-by-step instructions or point me to the necessary configuration files (like inputs.conf) or documentation to correctly set this up for:

  • Subscription to O365 audit logs
  • Graph API integration
  • Event collection

Additionally, if there are any known challenges or limitations specific to the China tenant setup, I’d appreciate insights on those as well.

Thank you in advance for your guidance!

Tilakram

Labels (1)
0 Karma

Meett
Splunk Employee
Splunk Employee

Hello @Tilakram Add-on doesn’t support Azure china ByDefault so i am afraid if it will work or not.

0 Karma

Tilakram
New Member

Hello @Meett ,

Thank you for the quick response! I appreciate your insight.

If the Splunk Add-on for Microsoft Office 365 doesn’t natively support Azure China, are there any recommended workarounds or custom configurations (e.g., modifying inputs.conf or using custom scripts) that could enable data collection for China tenants?

Alternatively, are there other Splunk-supported methods or integrations that you’d recommend for ingesting Microsoft Office 365 logs from Azure China tenants? For instance, could a custom API integration with the Graph API endpoint https://microsoftgraph.chinacloudapi.cn be a feasible approach?

Looking forward to your thoughts!

Regards,
Tilakram

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...