<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612604#M77598</link>
    <description>&lt;P&gt;Thanks for your reply &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/109095"&gt;@jconger&lt;/a&gt;. I did try to recreate the input and restart splunkd on the forwarder. I've also given it the ReportingWebService.Read.All under Applications permissions as stated here&amp;nbsp;&lt;A href="https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/" target="_blank"&gt;https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/&lt;/A&gt;&amp;nbsp;as well as Exchange Administrator and Global Reader role.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-09-09 at 17.18.34.png" style="width: 289px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21411iF7DE7670302E18C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2022-09-09 at 17.18.34.png" alt="Screenshot 2022-09-09 at 17.18.34.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2022 15:26:01 GMT</pubDate>
    <dc:creator>ljramv</dc:creator>
    <dc:date>2022-09-09T15:26:01Z</dc:date>
    <item>
      <title>Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/609632#M77413</link>
      <description>&lt;P&gt;We've upgrade this add-on to version 2.2.0 and &lt;SPAN&gt;Using Modern Authentication (OAuth), when configured in HF, the internal log shows 404 error as below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;127.0.0.1 - splunk-system-user [14/Aug/2022:20:08:03.558 -0700] "GET /servicesNS/nobody/TA-MS_O365_Reporting/storage/collections/data/TA_MS_O365_Reporting_checkpointer/MDSLAB_obj_checkpoint_oauth HTTP/1.1" 404 140 "-" "curl" - 1ms&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Would anybody can know the cause of this error? Any solutions? Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 13:20:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/609632#M77413</guid>
      <dc:creator>Lia</dc:creator>
      <dc:date>2022-08-16T13:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/610289#M77458</link>
      <description>&lt;P&gt;Having the same issue, keen to hear any solutions.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 06:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/610289#M77458</guid>
      <dc:creator>kissmyuzi123</dc:creator>
      <dc:date>2022-08-22T06:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612549#M77593</link>
      <description>&lt;P&gt;Hello, has anyone been able to configure the add-on with modern auth? Im getting this same error along with&amp;nbsp;&lt;SPAN class=""&gt;401&lt;/SPAN&gt; &lt;SPAN class=""&gt;Client&lt;/SPAN&gt; &lt;SPAN class=""&gt;Error:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Unauthorized&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;url:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;A href="https://reports.office365.com/ecp/reportingwebservice/reporting.svc" target="_blank" rel="noopener"&gt;https://reports.office365.com/ecp/reportingwebservice/reporting.svc&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Followed all the steps, &lt;A href="https://docs.microsoft.com/en-us/previous-versions/office/developer/o365-enterprise-developers/jj984325(v=office.15)" target="_self"&gt;the MS official doc&lt;/A&gt; also suggest to add Security Reader role for the App Registration. Shouldn't in theory there be an option to specify the tenant along with client ID and secret? Maybe&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/109095"&gt;@jconger&lt;/a&gt;&amp;nbsp;might know this one.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks for anyone's reply.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612549#M77593</guid>
      <dc:creator>ljramv</dc:creator>
      <dc:date>2022-09-09T12:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612594#M77596</link>
      <description>&lt;P&gt;That 404 error indicates a KV store issue.&amp;nbsp; Try cloning your input and then disabling or deleting the existing input.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 15:08:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612594#M77596</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2022-09-09T15:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612598#M77597</link>
      <description>&lt;P&gt;Setting up the permissions for this add-on is a 2 step process:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For the Azure AD app registration, add the ReportingWebService.Read.All API permission.&lt;UL&gt;&lt;LI&gt;This can be found by going to APIs my organization uses =&amp;gt; Office 365 Exchange Online.&amp;nbsp; See the attached screenshot&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;The Azure AD app registration needs to be assigned a directory role.&lt;UL&gt;&lt;LI&gt;The minimum role that works is Global Reader.&amp;nbsp; Here is a walkthrough on how to do that =&amp;gt;&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/roles/manage-roles-portal" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/active-directory/roles/manage-roles-portal&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="message_trace_api_permissions.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21409i94D3EC0BE14D1E93/image-size/large?v=v2&amp;amp;px=999" role="button" title="message_trace_api_permissions.jpg" alt="message_trace_api_permissions.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 15:15:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612598#M77597</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2022-09-09T15:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612604#M77598</link>
      <description>&lt;P&gt;Thanks for your reply &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/109095"&gt;@jconger&lt;/a&gt;. I did try to recreate the input and restart splunkd on the forwarder. I've also given it the ReportingWebService.Read.All under Applications permissions as stated here&amp;nbsp;&lt;A href="https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/" target="_blank"&gt;https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/&lt;/A&gt;&amp;nbsp;as well as Exchange Administrator and Global Reader role.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-09-09 at 17.18.34.png" style="width: 289px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21411iF7DE7670302E18C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2022-09-09 at 17.18.34.png" alt="Screenshot 2022-09-09 at 17.18.34.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 15:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612604#M77598</guid>
      <dc:creator>ljramv</dc:creator>
      <dc:date>2022-09-09T15:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612608#M77599</link>
      <description>&lt;P&gt;Was the API permission granted?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="message_trace_api_granted.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21413iA2B814E6D6B5E286/image-size/large?v=v2&amp;amp;px=999" role="button" title="message_trace_api_granted.jpg" alt="message_trace_api_granted.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also, was the role added at the directory level?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mesage_trace_roles.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21414iD1BEDF5C59C236D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="mesage_trace_roles.jpg" alt="mesage_trace_roles.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The input recreation suggestion was for the OP since they were getting a 404 on the KV store.&lt;/P&gt;&lt;P&gt;A question about the tenant was mentioned in the thread above.&amp;nbsp; The tenant is specified at the input level.&amp;nbsp; Are you setting up a "&lt;SPAN&gt;Microsoft Office 365 Message Trace (OAuth)" input?&amp;nbsp; That input requires the tenant ID; whereas, the "Microsoft Office 365 Message Trace (Basic Auth)" input does not.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 15:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612608#M77599</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2022-09-09T15:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Office 365 Reporting Web Service 2.0.0 404 ERROR- How to resolve?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612699#M77601</link>
      <description>&lt;P&gt;Ah theres the problem then, thank you. I did not create a new input but rather copy existing one that was set up with basic auth. Makes more sense for the tenant field to be specified on the account along with the client and secret. Thanks anyway.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 07:40:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Office-365-Reporting-Web-Service-2-0/m-p/612699#M77601</guid>
      <dc:creator>ljramv</dc:creator>
      <dc:date>2022-09-12T07:40:53Z</dc:date>
    </item>
  </channel>
</rss>

