I have the Trial version of Splunk with the Microsoft 365 App. How do I link Office 365 with Splunk.
As others have said, you do need the Splunk Add-On for Microsoft Office 365 to onboard the data, but if you already have the M365 App for Splunk installed, it has a really helpful visual setup guide that walks you through the whole process of on-boarding O365, from Azure App registration to configuring the O365 Add-On.
Splunk apps typically visualize data, while Splunk add-on typically gather data. The M365 app relies on the Splunk Add-on for Microsoft Office 365 to gather the necessary data.
In addition to the app, you also need an add-on for MS365 (add-ons collect data that apps display). There are several add-ons available on splunkbase. The documentation for them should explain what you need to do both in Splunk and in 365 to get data into Splunk.