<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does Splunk Add-on for Microsoft Office 365 has credential errors with only 1 input? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591505#M76459</link>
    <description>&lt;P&gt;I have the Splunk Add-on for Microsoft Office 365 app running and collecting all of the inputs successfully with t he exception of the Audit Logs input. I have it collecting logs from multiple O365 tenants, and all of them have&amp;nbsp; the same errors with&amp;nbsp; the&amp;nbsp; Audit Log Input.&lt;/P&gt;
&lt;P&gt;The _internal&amp;nbsp; log has the errors indicating its an issue with the username and&amp;nbsp; credentials. This app doesn't using credentials, it uses keys.&amp;nbsp; The keys for the Azure app are valid, and not expired.&amp;nbsp; I can log in successfully to the tenant with the same credentials that are show in the error message.&lt;/P&gt;
&lt;P&gt;The error is below and has been sanitized.&lt;/P&gt;
&lt;P&gt;2022-03-30 09:10:08,938 level=DEBUG pid=8229 tid=MainThread logger=splunk_ta_o365.modinputs.graph_api.GraphApiConsumer pos=GraphApiConsumer.py:_ingest:79 | datainput=b'se_audit_log_signins' start_time=1648645805 | message="ingesting message " message=graphApiMessage(id='XXXXXXXX-YYYY-XXX5-YYYY-ZZZZZZZZ', update_time=datetime.datetime(2022, 3, 30, 13, 10, 8, 751629), data='{"id": "XXXXXXXX-aXX-4cXXX-XXXX-XXXXXXXX", "createdDateTime": "2022-03-29T14:44:07Z", "userDisplayName": "XXXX XXXX", "userPrincipalName": "XXXX@YYYY.com", "userId": "XXXXXXXXXXXXXXXXXX", "appId": "00000002-0000-0ff1-ce00-000000000000", "appDisplayName": "Office 365 Exchange Online", "ipAddress": "123.123.122.123", "clientAppUsed": "Reporting Web Services", "correlationId": "XXXXXXXX-YYYY-ZZZZ-QQQQQQQQ", "conditionalAccessStatus": "notApplied", "isInteractive": true, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName": "Office 365 Exchange Online", "resourceId": "XXXXXXXX-0000-0XXX-XX00-000000000000", "status": {"errorCode": 50126, "failureReason": "Error validating credentials due to invalid username or password.", "additionalDetails": "The user didn\'t enter the right credentials. \\u00a0It\'s expected to see some number of these errors in your logs due to users making mistakes."}, "deviceDetail": {"deviceId": "", "displayName": "", "operatingSystem": "", "browser": "Python Requests 2.22", "isCompliant": false, "isManaged": false, "trustType": ""}, "location": {"city": "somewhere", "state": "XXXXXX", "countryOrRegion": "US", "geoCoordinates": {"altitude": null, "latitude": XX.XXXX, "longitude": -XX.XXXX}}, "appliedConditionalAccessPolicies": []}', key='XXXXXX-XXXX-XXXX-XX-XXXXXXXXX')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts?&amp;nbsp; Its working for all other inputs.&lt;/P&gt;
&lt;P&gt;Thanks, Robert&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 17:29:50 GMT</pubDate>
    <dc:creator>robayers</dc:creator>
    <dc:date>2022-03-30T17:29:50Z</dc:date>
    <item>
      <title>Why does Splunk Add-on for Microsoft Office 365 has credential errors with only 1 input?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591505#M76459</link>
      <description>&lt;P&gt;I have the Splunk Add-on for Microsoft Office 365 app running and collecting all of the inputs successfully with t he exception of the Audit Logs input. I have it collecting logs from multiple O365 tenants, and all of them have&amp;nbsp; the same errors with&amp;nbsp; the&amp;nbsp; Audit Log Input.&lt;/P&gt;
&lt;P&gt;The _internal&amp;nbsp; log has the errors indicating its an issue with the username and&amp;nbsp; credentials. This app doesn't using credentials, it uses keys.&amp;nbsp; The keys for the Azure app are valid, and not expired.&amp;nbsp; I can log in successfully to the tenant with the same credentials that are show in the error message.&lt;/P&gt;
&lt;P&gt;The error is below and has been sanitized.&lt;/P&gt;
&lt;P&gt;2022-03-30 09:10:08,938 level=DEBUG pid=8229 tid=MainThread logger=splunk_ta_o365.modinputs.graph_api.GraphApiConsumer pos=GraphApiConsumer.py:_ingest:79 | datainput=b'se_audit_log_signins' start_time=1648645805 | message="ingesting message " message=graphApiMessage(id='XXXXXXXX-YYYY-XXX5-YYYY-ZZZZZZZZ', update_time=datetime.datetime(2022, 3, 30, 13, 10, 8, 751629), data='{"id": "XXXXXXXX-aXX-4cXXX-XXXX-XXXXXXXX", "createdDateTime": "2022-03-29T14:44:07Z", "userDisplayName": "XXXX XXXX", "userPrincipalName": "XXXX@YYYY.com", "userId": "XXXXXXXXXXXXXXXXXX", "appId": "00000002-0000-0ff1-ce00-000000000000", "appDisplayName": "Office 365 Exchange Online", "ipAddress": "123.123.122.123", "clientAppUsed": "Reporting Web Services", "correlationId": "XXXXXXXX-YYYY-ZZZZ-QQQQQQQQ", "conditionalAccessStatus": "notApplied", "isInteractive": true, "riskDetail": "none", "riskLevelAggregated": "none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes": [], "riskEventTypes_v2": [], "resourceDisplayName": "Office 365 Exchange Online", "resourceId": "XXXXXXXX-0000-0XXX-XX00-000000000000", "status": {"errorCode": 50126, "failureReason": "Error validating credentials due to invalid username or password.", "additionalDetails": "The user didn\'t enter the right credentials. \\u00a0It\'s expected to see some number of these errors in your logs due to users making mistakes."}, "deviceDetail": {"deviceId": "", "displayName": "", "operatingSystem": "", "browser": "Python Requests 2.22", "isCompliant": false, "isManaged": false, "trustType": ""}, "location": {"city": "somewhere", "state": "XXXXXX", "countryOrRegion": "US", "geoCoordinates": {"altitude": null, "latitude": XX.XXXX, "longitude": -XX.XXXX}}, "appliedConditionalAccessPolicies": []}', key='XXXXXX-XXXX-XXXX-XX-XXXXXXXXX')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts?&amp;nbsp; Its working for all other inputs.&lt;/P&gt;
&lt;P&gt;Thanks, Robert&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591505#M76459</guid>
      <dc:creator>robayers</dc:creator>
      <dc:date>2022-03-30T17:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 has credential errors with only 1 input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591525#M76460</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229375"&gt;@robayers&lt;/a&gt;&amp;nbsp;- This sounds weird error message, considering you are using the same account for all other inputs as well.&lt;/P&gt;&lt;P&gt;- Just make sure your credentials (Client ID and Client Secret) have not been expired on Azure App.&lt;/P&gt;&lt;P&gt;For the safeguard, I would just check whether Azure App that you are using for credentials has the right permissions or not.&lt;/P&gt;&lt;P&gt;Following are the permission required:&lt;/P&gt;&lt;TABLE border="1" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="197px" height="201px"&gt;&lt;DIV&gt;Office 365 Management APIs&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="350px" height="201px"&gt;&lt;DIV&gt;(Application) ActivityFeed.Read&lt;BR /&gt;(Application) ServiceHealth.Read&lt;BR /&gt;(Application) ActivityFeed.ReadDlp (if collecting DLP data)&lt;BR /&gt;&lt;BR /&gt;(Delegated) ActivityFeed.Read&lt;BR /&gt;(Delegated) ServiceHealth.Read&lt;BR /&gt;(Delegated) ActivityFeed.ReadDlp (if collecting DLP data)&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="80.75px" height="201px"&gt;&lt;P&gt;Microsoft&lt;/P&gt;&lt;P&gt;Graph&lt;/P&gt;&lt;/TD&gt;&lt;TD width="140.05px" height="201px"&gt;(Application) AuditLog.Read.All&lt;BR /&gt;(Application) Policy.Read.All&lt;BR /&gt;(Application) Reports.Read.All&lt;BR /&gt;(Application) Directory.Read.All&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 14:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591525#M76460</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-30T14:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk Add-on for Microsoft Office 365 has credential errors with only 1 input?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591608#M76466</link>
      <description>&lt;P&gt;I've confirmed all of the above permissions are set correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 18:44:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591608#M76466</guid>
      <dc:creator>robayers</dc:creator>
      <dc:date>2022-03-30T18:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk Add-on for Microsoft Office 365 has credential errors with only 1 input?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591641#M76468</link>
      <description>&lt;P&gt;No Luck, all&amp;nbsp; permissions checked, secret key and expiration checked, still getting the errors.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 00:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591641#M76468</guid>
      <dc:creator>robayers</dc:creator>
      <dc:date>2022-03-31T00:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk Add-on for Microsoft Office 365 has credential errors with only 1 input?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591670#M76469</link>
      <description>&lt;P&gt;&amp;nbsp;Just make sure there is no manual code modification that has been done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To make sure you have all the right files available from the Add-on:&lt;/P&gt;&lt;P&gt;Upgrade to the latest version (perform the upgrade even though you are already on the latest version) of the Add-on and reconfigure that particular input.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 05:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-Splunk-Add-on-for-Microsoft-Office-365-has-credential/m-p/591670#M76469</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-31T05:23:38Z</dc:date>
    </item>
  </channel>
</rss>

