-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SIEM] Office 365 module #16386
Merged
Merged
[SIEM] Office 365 module #16386
Commits on Mar 18, 2020
-
New module o365 for Office 365 log ingestion
This includes a new fileset, o365.audit, that uses the o365audit input to ingest logs using the Office 365 Management API.
Configuration menu - View commit details
-
Copy full SHA for 8aa512b - Browse repository at this point
Copy the full SHA 8aa512bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 4eb820a - Browse repository at this point
Copy the full SHA 4eb820aView commit details -
Configuration menu - View commit details
-
Copy full SHA for ee4d2ac - Browse repository at this point
Copy the full SHA ee4d2acView commit details -
Configuration menu - View commit details
-
Copy full SHA for d1c4934 - Browse repository at this point
Copy the full SHA d1c4934View commit details -
Configuration menu - View commit details
-
Copy full SHA for c969d6f - Browse repository at this point
Copy the full SHA c969d6fView commit details -
Convert numeric user.id to string
Avoid error when trying to dissect.
Configuration menu - View commit details
-
Copy full SHA for 454ffeb - Browse repository at this point
Copy the full SHA 454ffebView commit details -
Configuration menu - View commit details
-
Copy full SHA for 277c9a5 - Browse repository at this point
Copy the full SHA 277c9a5View commit details -
Configuration menu - View commit details
-
Copy full SHA for c8a6b62 - Browse repository at this point
Copy the full SHA c8a6b62View commit details -
Max retention is 7 days, that's 168h, not 178.
Configuration menu - View commit details
-
Copy full SHA for 02ea070 - Browse repository at this point
Copy the full SHA 02ea070View commit details -
Append https scheme to endpoint URLs if needed
This patches the o365audit input to accept resource and authentication_endpoint configuration options without a scheme.
Configuration menu - View commit details
-
Copy full SHA for 2712947 - Browse repository at this point
Copy the full SHA 2712947View commit details -
Configuration menu - View commit details
-
Copy full SHA for 3adebc7 - Browse repository at this point
Copy the full SHA 3adebc7View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8181a9b - Browse repository at this point
Copy the full SHA 8181a9bView commit details -