Splunk® Supported Add-ons

Splunk Add-on for Microsoft Security

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for Microsoft Security

About this release

Version 2.1.1 of the Splunk Add-on for Microsoft Security was released on July 13, 2023. It is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 9.0.x
CIM 5.0.1
Platforms Platform independent
Vendor Products Microsoft 365 Defender, Defender for Endpoint

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

Version 2.1.1 of the Splunk Add-on for Microsoft Security has the following new features.

  • Fixes the issue of proxy not being used while creating/updating inputs.


CIM Data Model Changes

There are no CIM Data Model changes between the Splunk add-on for Microsoft Security v2.1.0 and v2.1.1.



Fixed issues

Version 2.1.1 of the Splunk Add-on for Microsoft Security contains the following fixed issues.


Date resolved Issue number Description
2023-07-31 ADDON-63131 Proxy details not used while creating/updating the input

Known issues

Version 2.1.1 of the Splunk Add-on for Microsoft Security contains the following known issues. If no issues appear below, no issues have yet been reported:



Third-party software attributions

The Splunk Add-on for Microsoft Security incorporates the following third-party software or libraries: Media:MS-Security-v2.1.0-third-party.pdf

Last modified on 28 November, 2023
PREVIOUS
Source types for the Splunk Add-on for Microsoft Security
  NEXT
Release history

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters