File tree Expand file tree Collapse file tree 1 file changed +16
-0
lines changed Expand file tree Collapse file tree 1 file changed +16
-0
lines changed Original file line number Diff line number Diff line change
1
+ name : Office 365 Reporting Message Trace
2
+ id : b637788e-fcf0-44fa-86ea-cab81193f939
3
+ version : 1
4
+ date : ' 2025-02-28'
5
+ author : Steven Dick
6
+ description : Data source object for Office 365 Reporting Message Trace
7
+ source : o365
8
+ sourcetype : o365:reporting:messagetrace
9
+ separator : Organization
10
+ supported_TA :
11
+ - name : Splunk Microsoft Office 365 Add-on
12
+ url : https://splunkbase.splunk.com/app/4055
13
+ version : 4.8.0
14
+ fields :
15
+ - _time
16
+ example_log :
' {"Organization": "attackrange.onmicrosoft.com", "MessageId": "<BY5PR08MB62304A5BB7F9EE555B4CEA26DC1C2@BY5PR08MB6230.namprd08.prod.outlook.com>", "Received": "2025-01-16T21:06:46.832439", "SenderAddress": "victim_2@attack_range.lan", "RecipientAddress": "[email protected] ", "Subject": "Accounts and Passwords", "Status": "Delivered", "ToIP": "2607:f8b0:400e:c0d::1a", "FromIP": "189.135.168.197", "Size": 33584, "MessageTraceId": "3567c8ef-cc17-4a3f-d166-08dd3161e4fc", "Index": 3035}'
You can’t perform that action at this time.
0 commit comments