All Apps and Add-ons

Configuration page doesn't work for Splunk Add-on for Office 365

stevenjluke
Explorer

I just install the Splunk Add-on for Microsoft Office 365. The current directions say click on the tenant tab. There isn't once but there is a configuration tab. When I click on the configuration tab all I get is a page with an html link that takes me back to the main splunk page.

The only version I can download is 2.0 which just came out. Is there an issue with the new release? How can I configure a tenant?

uagrawal_splunk
Splunk Employee
Splunk Employee

No, there is no issue with the newer version of Splunk Add-On for Office 365.
In the new release, Tenant and Setting pages are restricted to admin only for security concerns. Refer to New features: https://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes
If you want to access the UI of the Tenant and settings page, then you need admin credentials.

vector_sec
New Member

I'm signed in as admin and the https://[my splunk hostname]/en-US/app/splunk_ta_o365/configuration page never loads, looking at inspect element all of the JS/HTML files are returning 404s. Running version 2.0.0 of the Add-on and version 7.2.7 of Splunk Enterprise.

Any ideas?

0 Karma

uagrawal_splunk
Splunk Employee
Splunk Employee

@vector_sec
The Splunk Add-On for Office 365 consists of a Tenant and Input page where you can do your Configuration.
So I think below link will work for you:
For tenant configuration: https ://[splunk hostname:port]/en-US/app/splunk_ta_o365/tenant
For Input Configuration: https ://[splunk hostname:port]/en-US/app/splunk_ta_o365/input
For logging and proxy settings: https: //[splunk hostname:port]/en-US/app/splunk_ta_o365/settings

0 Karma

marycordova
SplunkTrust
SplunkTrust

If you have access to an Azure environment there is a better way to get O365 logs by passing them through Azure than using an API based app: https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html

@marycordova
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...