Skip to main content
Splunk Add-on for Microsoft Office 365 app icon

Splunk Add-on for Microsoft Office 365

The Splunk Add-on for Microsoft Office 365 allows a Splunk software administrator to pull service status, service messages, and management activity logs from the Office 365 Management API. You can collect:Built by Splunk LLC
splunk product badge

Default Version 6.1.0

July 30, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

CIM Version: 5.x

Rating
3
(23)

Log in to rate this app

Support
Splunk Supported
Ranking

#7 in IT Operations

The Splunk Add-on for Microsoft Office 365 allows a Splunk software administrator to pull service status, service messages, and management activity logs from the Office 365 Management API. You can collect: * Audit logs for Azure Active Directory, Sharepoint Online, and Exchange Online, supported by the Office 365 Management API. * Historical and current service status, and service messages for the corresponding Microsoft Office 365 Management API. * Data Loss Prevention on Microsoft Office 365 Management API. After the Splunk platform indexes the events, you can then directly analyze the data or use it as a contextual data feed to correlate with other data in the Splunk platform