Getting Data In

Which add-on for o365 and Azure log collection?

ojay
Path Finder

Hi all,

I am planning on integrating o365 and Azure cloud services to my Splunk on-prem environment.

Now there are several Add-Ons to choose from in Splunkase

  • Microsoft Azure Add on for Splunk
  • Splunk Add-on for Microsoft Office 365
  • Splunk Add-on for Microsoft Cloud Services

What is the main difference between these Add-Ons and which should i use? The documentation did not really help.

"The Splunk Add-on for Microsoft Office 365 replaces the modular input for the Office 365 Management API within the Splunk Add-on for Microsoft Cloud Services."

  • Is it still possible to collect the o365 logs with the Cloud Services add-on which collects via so called event hubs?
  •  

Thank you,

O.

Tags (3)
0 Karma

ojay
Path Finder

In case i use both add-on's do I need to create two seperate application integrations?

0 Karma

ojay
Path Finder

Thank you for the quick feedback, the guide is helpful but i was more looking into a comparison about what add-on to use.

Is the "Splunk Add-on for Microsoft Cloud Services" able to get the O365 data? Is it advised to use it?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

we have used this instructions 

https://www.ciraltos.com/use-splunk-to-collect-logs-from-office-365-and-azure-ad/ to setup M365 data collection and presentation. This guide is little bit outdated, but you could manage configuration with small modifications.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...