1Security + Splunk
Splunk searches what happened. 1Security tells it who could reach what.
Splunk is where your SOC lives: every source, one search language, alerts ranked by risk. 1Security connects to your Microsoft 365 tenant read-only and gives Splunk the piece a raw audit event does not carry - which user, on which device, from which city, touched which file, and how many more files that account could open. Your searches start from a row that already answers the first three questions.
What Splunk does
The SIEM of record, and the workflow around it.
One place for every log your organization emits, and a detection practice built on top of it.
Every source, one search language
Splunk Enterprise collects machine data from thousands of sources at terabyte scale, with more than 2,300 out-of-the-box integrations and one search language across all of it. If it happened and it was logged, a search will find it.
Alerts ranked by risk
Splunk Enterprise Security brings SIEM, SOAR and UEBA together in one platform. Risk-based alerting cuts alert volume by up to 90%, so analysts spend their time on threats rather than on a queue.
Detection engineering with coverage you can see
Detection Studio runs the detection lifecycle end to end, mapped to MITRE ATT&CK and enriched with Cisco Talos threat intelligence. Your coverage is a chart, not a guess.
The question this pairing answers
A log line says what happened. It does not say what it could have reached.
A Splunk detection names an account at 02:14. The next three questions are always the same: who is this, what can they open, and is tonight normal for them? Those answers do not live in any event, because standing permissions in Microsoft 365 are state, not activity. A sharing link created in 2023 writes nothing tonight. A nested group extends reach to a site no log line mentions. In a typical tenant an ordinary account can open more than 200,000 files, and nothing in the audit stream says so.
So the analyst leaves Splunk to find out - permission dialogs, group memberships, a script per site - and comes back an hour later with an estimate. That hour is the whole cost of the alert, and it is paid on false positives too.
1Security keeps that answer ready. It resolves what every user, guest, app and AI agent can reach through direct grants, sharing links, groups and inheritance, keeps up to three years of attributed activity, and hands Splunk events that already carry the context. The detection still fires in Splunk. The hour goes away.
What 1Security adds
Four things Splunk gets from the tenant that it did not have before.
1Security connects read-only to Microsoft 365, builds the permission graph and the activity history, and serves both to Splunk through a read-only REST API.
- 01
Reach on every event
Each Microsoft 365 event 1Security emits is tied to the user, the file or mailbox, the app, the device and the location, and the account behind it comes with what it can open: sites, files, mailboxes, resolved through nesting, links and inheritance. A blast-radius question that took half a day is a field on the row.
- 02
A baseline for every account
Every user, app and AI agent is scored against its own trailing activity. "340 downloads today" arrives already compared with the usual 12, with an anomaly episode Splunk can correlate on. Up to three years of history sits behind it on standard Microsoft 365 licenses.
- 03
Devices and locations, not just IPs
Every event carries the device (managed, unmanaged or never enrolled) and the location as country, city and network type - hosting, VPN, office. An impossible-travel verdict is a value in the row, not a search you write.
- 04
A fix that waits for a human
When Splunk escalates, the fix happens in 1Security behind a review window - expire the links, remove the access, revoke the sessions - staged per resource, 72 hours by default, and logged with who approved it. Nothing irreversible runs on an automation alone.
How the two fit
Splunk keeps the record and the workflow. 1Security keeps the context.
Splunk stays the SIEM of record: the index, the detections, the automated response, the case. 1Security connects to your Microsoft 365 tenant with read-only consent - no agents, standard licenses, first findings the same day - and maintains what a log stream cannot: the resolved permission graph, the per-account baselines and three years of attributed history. Splunk pulls 1Security audit logs, monitoring alerts and security alerts from the read-only REST API on a schedule, and every row arrives with the who, the device, the location and the reach already attached. When an analyst needs the full picture, one click opens the account in 1Security.
- 1 dayfrom read-only consent to the first findings
- 10 minto a blast-radius answer that used to take half a day
- 3 yearsof attributed activity behind every alert
Together in practice
NIS2 gives you 24 hours. The scope should be a lookup, not a project.
NIS2 Article 23 puts a significant incident on a clock: an early warning within 24 hours of awareness, a full notification within 72, a final report after that. The regulator wants scope inside those windows - what was hit, how badly, and what it touched - not a promise to find out.
Splunk establishes the event chain: when it started, which systems were involved, what the detections and the automated response did. 1Security establishes the scope: every file, site and mailbox the affected account could reach, resolved in minutes, and what it actually touched, measured against three years of its own history. Both are in the row Splunk already holds.
The early warning ships with real numbers in it. The 72-hour notification cites 214,000 reachable files and 3,100 with personal data, not "potentially affected". And the remediation that follows is staged, reviewed and logged, so the final report has a timeline of fixes to attach.
Integration
Pull-based, read-only, on your schedule.
Splunk pulls from the 1Security read-only REST API under /api/v1: normalized Microsoft 365 audit logs enriched with user, file, device, location and reach; monitoring alerts raised by your policies; and Defender or Sentinel security alerts with the same context. Keys are per tenant, scoped and read-only, so a Splunk collector can read the data and change nothing in 1Security or in Microsoft 365. Outbound webhook delivery is planned; until it ships, scheduled polling is the supported pattern.
Give your Splunk alerts the who, the reach and the history.
Connect 1Security read-only and point Splunk at the API. Your next Microsoft 365 detection arrives with the account, its reach and its baseline already on the row.
Or keep leaving Splunk to answer the first three questions by hand.