Files
splunk-security_content/macros/m365_copilot_graph_api.yml
Rod Soto 6cf5b0f8f6 Copilot based Detections (#3693)
* det1

* fixeddt1

* det2

* d3

* det4

* djbk

* d6

* d7

* d8

* addedlnkds

* fixsctype

* pipegone

* fixp

* fixdevices

* jbfix

* datasetfix

* exp

* fixsynthax

* changedstory

* changeprinus

* improvedht

* changedSenderuser

* datas

* fixdoublesearch

* fixedpi

* fixeddescriptionsuser

* fixdatalink

* exportedlogsdatasource

* fixedhowtodatasource

* updating risk stuff

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 12:14:09 -07:00

4 lines
265 B
YAML

definition: (sourcetype="o365:graph:api" OR source="AuditLogs.SignIns")
description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
name: m365_copilot_graph_api