Skip to content

Release notes for the Splunk Add-on for Microsoft Security

About this release

Version 4.0.0 of the Splunk Add-on for Microsoft Security was released on .

Compatibility

Version 4.0.0 is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 9.3.x, 9.4.x, 10.0.x, 10.2.x
CIM 8.5.x
Platforms Windows, Linux based Operating Systems
Vendor Products Microsoft 365 Defender, Defender for Endpoint, Azure Event Hubs, Microsoft Defender Threat Intelligence

Note

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

  • Observability Metrics

    • Integrated solnlib observability metrics into all modular inputs, enabling operational monitoring of collection health directly from Splunk.
  • Configurable Time Window Splitting

    • Graph API queries for Incidents and ATP Alerts inputs are now split into configurable time windows using the new Max Query Window parameter. This prevents HTTP 500 errors on high-volume tenants and improves reliability at scale.
  • HTTP Retry Logic

    • Automatic retry for transient HTTP 500 and HTTP 503 errors from Microsoft Graph API, reducing data gaps caused by temporary server-side failures.
  • Checkpoint Timestamp Precision Fix

    • Sub-second precision in checkpoint timestamps is now normalized, preventing duplicate or missed events caused by timestamp rounding inconsistencies.
  • Python 3.13 Support

    • All modular inputs now declare python.required = 3.9, 3.13. Python 3.7 support has been dropped.

Breaking changes

  • Dropped Python 3.7 support: The minimum supported Python version is now 3.9.
  • Dependency upgrades: Third-party libraries have been updated. The pytest-splunk-addon version has been changed and splunktafunctionaltests replaces the legacy modinput test framework.

Fixed issues

Version 4.0.0 of the Splunk Add-on for Microsoft Security fixes the following issues.

Known issues

Version 4.0.0 of the Splunk Add-on for Microsoft Security contains the following known issues.

Third-party software attributions

Version 4.0.0 incorporates third-party software attributions for the Splunk Add-on for Microsoft Security.