<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707059#M21126</link>
    <description>If you have multiple cores in that HF and if it runs e.g. DB Connect then you should add pipelines into it. That increase it's performance. Usually it's said that don't use more pipelines than 2 on your node unless it's physical server and it's HF. There are some articles/post/blogs about this, where you could found more information about it.</description>
    <pubDate>Tue, 17 Dec 2024 16:10:53 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-12-17T16:10:53Z</dc:date>
    <item>
      <title>Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/706876#M21099</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a Splunk indexer cluster with two searchheads and would like to use the addon in the cluster: &lt;A href="https://splunkbase.splunk.com/app/4055" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4055&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We installed the addon on the searchhead without ES and on all indexers via ClusterManager App.&lt;/P&gt;&lt;P&gt;Then we set up all the inputs for the addon on the searchhead and could not select the index “M365” but only enter it manually.&lt;/P&gt;&lt;P&gt;The problem now is that this index is not filled by the indexers!&lt;/P&gt;&lt;P&gt;What are we doing wrong here?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-12-16 115428.png" style="width: 719px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33852i8969029B2F8C8681/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-12-16 115428.png" alt="Screenshot 2024-12-16 115428.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-12-16 115517.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33853i25ACFEB8A8D1031A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-12-16 115517.png" alt="Screenshot 2024-12-16 115517.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-12-16 115555.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33854i4490C15A97982C47/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-12-16 115555.png" alt="Screenshot 2024-12-16 115555.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-12-16 115619.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33855i7BD8F96D5F33F7D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-12-16 115619.png" alt="Screenshot 2024-12-16 115619.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 10:59:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/706876#M21099</guid>
      <dc:creator>Serial98</dc:creator>
      <dc:date>2024-12-16T10:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/706958#M21108</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;i’m not sure if I understand correctly how you have installed ad configured it? Have you followed this instructions where to install it&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Install/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Install/&lt;/A&gt;&amp;nbsp;? And then followed this how to configure it&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureAppinAzureAD/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-microsoft-office-365/ConfigureAppinAzureAD/&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;Following those steps it should work. If not then you should look troubleshooting from here&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Troubleshooting/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-microsoft-office-365/Troubleshooting/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 21:31:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/706958#M21108</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-16T21:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/706971#M21111</link>
      <description>&lt;P&gt;First and foremost - you should not configure inputs on a search head. Set up a separate HF with those inputs and only use SHs for searching.&lt;/P&gt;&lt;P&gt;There might be more issues with your overall setup that we don't know about.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 23:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/706971#M21111</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-16T23:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707023#M21120</link>
      <description>&lt;P&gt;Thanks for the quick replies, we have configured a HF and removed the input from the SH.&lt;/P&gt;&lt;P&gt;With the help of the guides we also managed to set the necessary EntraID permissions for the app.&lt;/P&gt;&lt;P&gt;Now it works and all dashboards show data.&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 11:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707023#M21120</guid>
      <dc:creator>Serial98</dc:creator>
      <dc:date>2024-12-17T11:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707036#M21122</link>
      <description>As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt; said, you should use separate HF in distributed environment for all modular inputs, don’t put those into SH. Of course you need TA in SH too, but not inputs configured there.</description>
      <pubDate>Tue, 17 Dec 2024 13:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707036#M21122</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-17T13:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707041#M21123</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;many thanks for the advice, we have now seperated all inputs to the HF. SH is now just for searching but has the TA installed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; many thanks also for the hint!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 14:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707041#M21123</guid>
      <dc:creator>Serial98</dc:creator>
      <dc:date>2024-12-17T14:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Setup M365 Index on Indexer Cluster with two Searchheads (normal and ES)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707059#M21126</link>
      <description>If you have multiple cores in that HF and if it runs e.g. DB Connect then you should add pipelines into it. That increase it's performance. Usually it's said that don't use more pipelines than 2 on your node unless it's physical server and it's HF. There are some articles/post/blogs about this, where you could found more information about it.</description>
      <pubDate>Tue, 17 Dec 2024 16:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Setup-M365-Index-on-Indexer-Cluster-with-two-Searchheads-normal/m-p/707059#M21126</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-17T16:10:53Z</dc:date>
    </item>
  </channel>
</rss>

