All Apps and Add-ons

Configuration page doesn't work for Splunk Add-on for Office 365

stevenjluke
Explorer

I just install the Splunk Add-on for Microsoft Office 365. The current directions say click on the tenant tab. There isn't once but there is a configuration tab. When I click on the configuration tab all I get is a page with an html link that takes me back to the main splunk page.

The only version I can download is 2.0 which just came out. Is there an issue with the new release? How can I configure a tenant?

uagrawal_splunk
Splunk Employee
Splunk Employee

No, there is no issue with the newer version of Splunk Add-On for Office 365.
In the new release, Tenant and Setting pages are restricted to admin only for security concerns. Refer to New features: https://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes
If you want to access the UI of the Tenant and settings page, then you need admin credentials.

vector_sec
New Member

I'm signed in as admin and the https://[my splunk hostname]/en-US/app/splunk_ta_o365/configuration page never loads, looking at inspect element all of the JS/HTML files are returning 404s. Running version 2.0.0 of the Add-on and version 7.2.7 of Splunk Enterprise.

Any ideas?

0 Karma

uagrawal_splunk
Splunk Employee
Splunk Employee

@vector_sec
The Splunk Add-On for Office 365 consists of a Tenant and Input page where you can do your Configuration.
So I think below link will work for you:
For tenant configuration: https ://[splunk hostname:port]/en-US/app/splunk_ta_o365/tenant
For Input Configuration: https ://[splunk hostname:port]/en-US/app/splunk_ta_o365/input
For logging and proxy settings: https: //[splunk hostname:port]/en-US/app/splunk_ta_o365/settings

0 Karma

marycordova
SplunkTrust
SplunkTrust

If you have access to an Azure environment there is a better way to get O365 logs by passing them through Azure than using an API based app: https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html

@marycordova
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...