Hello,
We have the Splunk Add-on for Microsoft Cloud Services installed on a HWF and we are pulling through the following events.
Service Status,
Operational Message,
Exchange Online Audit,
Sharepoint Online Audit
Azure AD Audit
We don't seem to be getting any DLP (security & compliance) events or anything from audit.general either. Does anyone know what the issue might be?
Thanks
... View more