Im current using the Office 365 module but Im having several issues.
First, I use Logstash for processsing (mostly because I put data in daily indexes). All I do in Logstash is take the data and pass it to Elasticsearch. No filtering or anything.
The data Im getting is only AzureActiveDirectory type....I dont see any signins of type Exchange, Sharepoint, etc.
Also, when I try to get the built in dashboard it does see my data (module says that it is recieving data) BUT it does not load/look correctly. From what I am seeing, it tries loading from filebeat-* when it should be loading from another index (as I named it differently)
Can someone help me out on the Office 365 Module and using it with Logstash? Thanks.