The Microsoft Graph Security Score Add-on for Splunk allows users to collect their Azure (Office 365) Security Score from Microsoft's Security Graph API. It consists of Python scripts that collect the required/necessary data to configure the account information.
There are two ways to setup this app:
1. Standalone Mode:
* Install the
Microsoft Graph Security Score Add-on for Splunk.
2. Distributed Mode:
* The Add-on can be installed on search head, but it is not required. The Add-on configuration is not required on search head. (The Add-on contains a dashboard to show Microsoft Graph Security Score.)
* Install the
Microsoft Graph Security Score Add-on for Splunk on the heavy forwarder.
* Configure the Add-on to collect the required information from the Microsoft Graph API on the heavy forwarder.
* The Add-on do not support universal forwarder.
* The Add-on is not required on an indexer.
The Add-on needs to be installed on the Search Head and heavy forwarder.
Browse more apps.
Microsoft Graph Security Score Add-on.
Microsoft Graph Security Score Add-on for Splunk>
Inputon Splunk UI.
Create New Input.
|Name||Enter a unique name for the input.|
|Interval||Interval in seconds (how often the Add-on should collect the latest data from the Microsoft Graph API). The ideal value is between 3600 (1 hour) - 14400 (4 hours)|
|Index||Enter the index name in which the Graph API data will be stored in Splunk.|
|Azure AD Tenant ID||Obtain the Tenant ID (Directory) from Azure AD.|
|Application Id||Obtain the Application ID (Client) from Azure AD.|
|Client Secret||Obtain the Client Secret from Azure AD.|
TA-microsoft-graph-security-scorefolder from the
Changes to make compatible with the latest Splunk AppInspect - Dashboards version changed to 1.1.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.