O365 Event Source data flow

Hi all,

I was configuring O365 ES, I was wondering what’s the data flow since a collector is mandatory in the configuration:

  1. O365 > Collector > Insight IDR
  2. O365 > InsightIDR OR Insight IDR (request) > O365

I wasn’t able to find anything from the documentation.

Many thanks in advance for your reply.



Hi Davide,

Yes a Collector is required; the Collector will issue an API call and pull back what is returned from O365 using the https://manage.office.com/ endpoint.

So it would be, O365 < > Collector > R7 InsightIDR.


