Microsoft’s MessageTrace REST endpoint provides summary information about the processing of email messages through your organization’s Office 365 system in the last 30 days. You can use this metadata to detect and report on malicious activity including bulk emails, spoofed-domain emails, and data exfiltration.
How Does It Work
This is a built-in integration through the Cribl Stream’s Office 365 Message Trace Source.
Configure Stream to receive data from the Office 365 Management Activity API via Sources > Office 365 Message Trace.
Specify the poll interval, your Office 365 credentials, and optional parameters like the date range, log level, and timeout to use.
Stream will start receiving Office 365 Message Trace data as it becomes available.