splunk-microsoft-cloud-setup

Render offline onboarding assets for Microsoft cloud Splunk add-ons.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-microsoft-cloud-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-microsoft-cloud-setup
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-microsoft-cloud-setup
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-microsoft-cloud-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

The skill renders offline assets to accelerate onboarding of two Microsoft cloud Splunk add-ons (Office 365 and Microsoft Cloud Services) by producing inputs, runbooks, and index plans that are reviewable before deployment.

Core Features & Use Cases

  • Render offline assets for Office 365 add-on (splunk_ta_o365) and Microsoft Cloud Services add-on (Splunk_TA_microsoft-cloudservices), including inputs.conf stanzas, account-setup runbook, and CIM-aligned mappings.
  • Generate a ready-to-review deployment package with installation, validation guidance, and index creation steps for Splunk environments.
  • Use case: onboard Entra ID, Microsoft Graph metadata, and Azure audit data for cloud telemetry in Splunk.

Quick Start

Render the offline assets to review inputs, runbooks, and validation artifacts for both add-ons.

Frequently Asked Questions about splunk-microsoft-cloud-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I onboard Microsoft cloud data in Splunk using the Office 365 and Azure add-ons?

To onboard Microsoft cloud data in Splunk, this Skill renders offline reviewable assets including inputs.conf stanzas, account-setup runbooks, and index plans for the Office 365 and Microsoft Cloud Services add-ons.

What's the best way to generate inputs.conf stanzas for Entra ID and Azure audit logs in Splunk?

Generating inputs.conf stanzas for Entra ID and Azure audit logs is handled by rendering offline assets for the Microsoft Cloud Services and Office 365 add-ons, producing stanzas ready for review before deployment.

Does this Splunk onboarding package include CIM mappings for Office 365 Management Activity?

Yes, the Splunk onboarding package includes CIM-aligned mappings for Office 365 Management Activity, Entra ID metadata, and Azure audit data to ensure compatibility with Splunk dashboards.

Can I configure the Splunk add-on for just Entra ID metadata without generating files for both add-ons?

You can configure a single Splunk add-on for Entra ID metadata by using command options to render a subset of the offline assets, skipping the full Office 365 and Cloud Services deployment package.

Do I need to embed credentials when generating the Splunk Microsoft cloud deployment package?

No, you do not need to embed credentials; the Skill requires no embedded secrets and outputs a ready-to-review package containing installation and validation guidance for later deployment.

What validation guidance is provided for Splunk Microsoft cloud inputs deployment?

The package provides validation guidance for Splunk Microsoft cloud inputs by including index creation steps, account-setup runbooks, and installation instructions to verify data ingestion before finalizing.