Enable a saved search
You can populate the
public_ip fields in a lookup file that works with
Enable a saved search in the Splunk Add-on for Microsoft Cloud Services Object view in Splunk Web or in default/savedsearches.conf. You can set a schedule for the search to run on, and users can also run it manually.
Connect to your Microsoft Office 365 account with the Splunk Add-on for Microsoft Cloud Services
Configure Azure Event Hub inputs for the Splunk Add-on for Microsoft Cloud Services
This documentation applies to the following versions of Splunk® Supported Add-ons: released