Splunk® Supported Add-ons

Splunk Add-on for Microsoft Cloud Services

Download manual as PDF

Download topic as PDF

Splunk Add-on for Microsoft Cloud Services

Version 4.0.0
Vendor Products Azure Active Directory, Azure Storage Table, Azure Storage Blob, Azure Audit, Azure Resource Group
Add-on has a web UI Yes. This add-on contains views for configuration.

The Splunk Add-on for Microsoft Cloud Services allows a Splunk administrator to pull Azure audit, Azure resource data, and Azure Storage Table and Blob data from a variety of Microsoft Cloud services using the Azure Service Management APIs and Azure Storage APIs.

This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security, the Splunk App for PCI Compliance, and Splunk IT Service Intelligence.

Download the Splunk Add-on for Microsoft Cloud Services from Splunkbase.

For a summary of new features, fixed issues, and known issues, see Release Notes for the Splunk Add-on for Microsoft Cloud Services.

For information about installing and configuring the Splunk Add-on for Microsoft Cloud Services, see Installation overview for the Splunk Add-on for Microsoft Cloud Services.

See Questions related to Splunk Add-on for Microsoft Cloud Services on Splunk Answers.

Last modified on 22 October, 2019
Source types for the Splunk Add-on for Microsoft Cloud Services

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Hello Guarisma,
The ms:o365:management source type is still included in this add-on for backward compatibility. A similar source type, o365:management:activity, is in the Splunk Add-on for Microsoft 0ffice 365.

Mglauser splunk, Splunker
October 29, 2019

Seems office 365 support was removed from this Add-on but the documentation wasn't updated?

October 24, 2019

Hi everyone,

I am waiting for the eventhub implementation and read below that it is planned for future releases. When is the release scheduled that will contain eventhubs?

Kind regards,


January 16, 2019

Thanks for your question Lmorillogonzazlez. For issues like this, we suggest you post the question to Splunk Answers (http://answers.splunk.com) so the broader community of Splunk customers and employees can help you, and/or file a Support case via the Support portal (https://login.splunk.com/page/sso_redirect?type=portal) if you have an active Support entitlement.

Ccornell splunk, Splunker
November 27, 2018

Hi, Microsoft Cloud Services stop sending events to splunk, how can i solve this issue? I have the 2.0v

November 27, 2018

Can Splunk use Azure Block Blob Storage, I'm not referring to pulling activity logs, service status, but use it for Splunk Storage?

April 5, 2018

Thanks for asking, Chadmedeiros. Event Hub is currently not supported but this feature has already been planned for a future release.

Hunters splunk, Splunker
October 10, 2017

Hello, are there any plans for Event Hub integration?

September 29, 2017

Feature request: Able to query on the PartitionKey in table storage, instead of just time. I.e. add an option to filter on more than just time.

Add for intance an optional input and append it to mscs_storage_table_data_collector.py line 243: "PartitionKey >= '{}' and (Timestamp gt datetime'{}') and (Timestamp le datetime'{}')".format(part_key, start_time, end_time)

In tables with lots of rows the querying now is painfully slow.


August 25, 2017

Hi Ben
We don't support it now but I have forwarded your request to the PM. Thanks for your suggestion.

Rwang splunk, Splunker
July 16, 2017

Feature Request. Could someone add the ability to ingest PowerBI related logs from the O365 Management API ?

July 11, 2017

This add-on does not use powershell to get data in.

Rwang splunk, Splunker
May 23, 2017

Do you happen to have screen shots of what this will look like? Also does this utilize powershell on the backend to obtain data if so, Microsoft has a threshold on the amount of powershell commands https://www.cogmotive.com/blog/office-365-tips/office-365-exchange-online-powershell-throttling.

May 23, 2017

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters