<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Picking your brain - Splunk Add-on for Microsoft Office 365 - No Exchange Message Trace activity in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/683621#M2953</link>
    <description>&lt;P&gt;Hello jconger,&lt;/P&gt;&lt;P&gt;Thanks for the comment. My system admin did the registration and added the permissions during the original setup.&amp;nbsp; We're not getting any message trace data. I can ask him to double-check the roles, but as far as I know, it was done properly.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2024 16:45:49 GMT</pubDate>
    <dc:creator>jorge_1800</dc:creator>
    <dc:date>2024-04-08T16:45:49Z</dc:date>
    <item>
      <title>Picking your brain - Splunk Add-on for Microsoft Office 365 - No Exchange Message Trace activity</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/682499#M2920</link>
      <description>&lt;P&gt;Hello there, we're in process of deploying Splunk Cloud. We have installed the Microsoft Office 365 App for splunk along with all the required add-ons. The app is working as intended except that we're not getting any Message Trace data. We followed the instructions to properly setup the the Add-on Input and assigned the API permissions on the Azure side. For whatever reason we're still not getting any Trace Data. It looks like problem it's on the Azure side, we have assigned the appropriate API permissions as stated in the documentation. Is there anything else that needs to be setup on the Azure - or Splunk side to get Exchange Trace data?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We followed this instructions for Splunk add-on for Microsoft Office 365 integration.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSO365/ConfigureappinAzureAD" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSO365/ConfigureappinAzureAD&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any help would be highly appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 18:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/682499#M2920</guid>
      <dc:creator>jorge_1800</dc:creator>
      <dc:date>2024-03-30T18:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Picking your brain - Splunk Add-on for Microsoft Office 365 - No Exchange Message Trace activity</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/683437#M2947</link>
      <description>&lt;P&gt;The Message Trace input requires an additional step that isn't needed for the other inputs.&amp;nbsp; Did you add the Azure AD app registration to one of the following IAM roles?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Exchange Administrator&lt;/LI&gt;&lt;LI&gt;Global Administrator&lt;/LI&gt;&lt;LI&gt;Global Reader role (recommended)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSO365/Configureinputmessagetrace" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSO365/Configureinputmessagetrace&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 15:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/683437#M2947</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2024-04-05T15:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Picking your brain - Splunk Add-on for Microsoft Office 365 - No Exchange Message Trace activity</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/683621#M2953</link>
      <description>&lt;P&gt;Hello jconger,&lt;/P&gt;&lt;P&gt;Thanks for the comment. My system admin did the registration and added the permissions during the original setup.&amp;nbsp; We're not getting any message trace data. I can ask him to double-check the roles, but as far as I know, it was done properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 16:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Picking-your-brain-Splunk-Add-on-for-Microsoft-Office-365-No/m-p/683621#M2953</guid>
      <dc:creator>jorge_1800</dc:creator>
      <dc:date>2024-04-08T16:45:49Z</dc:date>
    </item>
  </channel>
</rss>

