Skip to content
Discussion options

You must be logged in to vote

All of those items should be supported via Elastic Integrations.

  1. Open up Elastic Fleet from the SOC interface.
  2. Click on Agent Policies at the top of the screen.
  3. Click on the Actions menu to the right of so-grid-nodes-general, then Duplicate policy.
  4. Give the new policy a name.
  5. Edit this new policy - click on Add Integration in the upper-right, then search for the M365 integration that you want.
  6. Click the Add button in the upper right corner of the integration screen.
  7. Put in all of the information for the M365 integration.
  8. Assign this new policy to one of the agents in your grid, so it can start retrieving the logs for you.

There's a video on our Youtube site for using the Elastic Integra…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Comment options

You must be logged in to vote
1 reply
@tsmith-spscc
Comment options

Answer selected by tsmith-spscc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
4 participants