All Apps and Add-ons

Support multiple Client IDs?

ChrisBell04
Communicator

It doesn't appear this addon supports multiple Client IDs (like the Splunk Add-on for Microsoft Cloud Services Addon)?

It would be great it this addon could leverage the existing settings/inputs present in the Splunk Add-on for Microsoft Cloud Services Addon, so one does not have duplicate client id/secrets for different addons on the same SH.

tobinbxnz
Explorer

I have to concur ... attempting to clone instances of the TA to cope with separate client_ids & tenants and it's doing my head in. Other than this limitation the TA works well. Multi-tenant capability would be #1 on the list of enhancements.

0 Karma

tobinbxnz
Explorer

Addition ... having the add-on cope with the latencies of the audit records in particular ... there are other solutions being proposed

0 Karma

troybebee
Engager

I agree, multi-tenant support is a big requirement to make this more useful. I am going to try to run 2 deployments at a time but it requires alot of regex changes to inputs/outputs.

0 Karma

Bloodnite
Path Finder

Any updates on updating the app to support this? I'd prefer not to clone the app /use a diff name or modify the existing app.

0 Karma

trevsmit
Engager

Moving the ClientID/Secret to the input configuration would be the best solution. I need to pull data from multiple Azure AD tenants and I really need this functionality!!

0 Karma

trevsmit
Engager

Moving the ClientID/Secret to the input configuration would be the best solution. I need to pull data from multiple Azure AD tenants and I really need this functionality!!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...