Release notes for the Splunk Add-on for Microsoft Security¶
About this release¶
Version 4.0.0 of the Splunk Add-on for Microsoft Security was released on
Compatibility¶
Version 4.0.0 is compatible with the following software, CIM versions, and platforms.
| Splunk platform versions | 9.3.x, 9.4.x, 10.0.x, 10.2.x |
|---|---|
| CIM | 8.5.x |
| Platforms | Windows, Linux based Operating Systems |
| Vendor Products | Microsoft 365 Defender, Defender for Endpoint, Azure Event Hubs, Microsoft Defender Threat Intelligence |
Note
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.
New features¶
-
Observability Metrics
- Integrated
solnlibobservability metrics into all modular inputs, enabling operational monitoring of collection health directly from Splunk.
- Integrated
-
Configurable Time Window Splitting
- Graph API queries for Incidents and ATP Alerts inputs are now split into configurable time windows using the new Max Query Window parameter. This prevents HTTP 500 errors on high-volume tenants and improves reliability at scale.
-
HTTP Retry Logic
- Automatic retry for transient HTTP 500 and HTTP 503 errors from Microsoft Graph API, reducing data gaps caused by temporary server-side failures.
-
Checkpoint Timestamp Precision Fix
- Sub-second precision in checkpoint timestamps is now normalized, preventing duplicate or missed events caused by timestamp rounding inconsistencies.
-
Python 3.13 Support
- All modular inputs now declare
python.required = 3.9, 3.13. Python 3.7 support has been dropped.
- All modular inputs now declare
Breaking changes¶
- Dropped Python 3.7 support: The minimum supported Python version is now 3.9.
- Dependency upgrades: Third-party libraries have been updated. The
pytest-splunk-addonversion has been changed andsplunktafunctionaltestsreplaces the legacy modinput test framework.
Fixed issues¶
Version 4.0.0 of the Splunk Add-on for Microsoft Security fixes the following issues.
Known issues¶
Version 4.0.0 of the Splunk Add-on for Microsoft Security contains the following known issues.
Third-party software attributions¶
Version 4.0.0 incorporates third-party software attributions for the Splunk Add-on for Microsoft Security.