Monitoring Splunk

Office 365 Administrator Audit Logs - How can I index them via script?

cmaier
Explorer

Just curious if anyone out there has had any experience getting their Office 365 Administrator Audit Logs into Splunk. They are easily downloadable via the ECP, but I'm looking to script something through PowerShell and have it grab the logs automagically.

Tags (1)
0 Karma

janetlavell
Engager

Hi,

We have just build a tool to do that and then some more...
SkyFormation Extend (c) for Splunk extracts security events from multiple business cloud applications (e.g. Salesforce, Google App, ServiceNow, Office 365,AWS,...) and transforms them into a unified and actionable stream of events sent to your Splunk or other SIEM solution of your choice.

No more cloud applications integration or classification worries, and all in unified form for easiest correlations and investigation across cloud apps.

SkyFormation is a Java app you can install at on-premise on any machine you want, and it will take you 5 minutes to set it up.

Please have a look at:
https://splunkbase.splunk.com/app/2932/

Feel more then welcome to ask me any question at support@skyformation.com

Best
Janet
www.skyformation.com

wbfoxii
Communicator

I'll be watching this very closely. I'm in the same state.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...