All Apps and Add-ons

Configuration page doesn't work for Splunk Add-on for Office 365

stevenjluke
Explorer

I just install the Splunk Add-on for Microsoft Office 365. The current directions say click on the tenant tab. There isn't once but there is a configuration tab. When I click on the configuration tab all I get is a page with an html link that takes me back to the main splunk page.

The only version I can download is 2.0 which just came out. Is there an issue with the new release? How can I configure a tenant?

uagrawal_splunk
Splunk Employee
Splunk Employee

No, there is no issue with the newer version of Splunk Add-On for Office 365.
In the new release, Tenant and Setting pages are restricted to admin only for security concerns. Refer to New features: https://docs.splunk.com/Documentation/AddOns/released/MSO365/Releasenotes
If you want to access the UI of the Tenant and settings page, then you need admin credentials.

vector_sec
New Member

I'm signed in as admin and the https://[my splunk hostname]/en-US/app/splunk_ta_o365/configuration page never loads, looking at inspect element all of the JS/HTML files are returning 404s. Running version 2.0.0 of the Add-on and version 7.2.7 of Splunk Enterprise.

Any ideas?

0 Karma

uagrawal_splunk
Splunk Employee
Splunk Employee

@vector_sec
The Splunk Add-On for Office 365 consists of a Tenant and Input page where you can do your Configuration.
So I think below link will work for you:
For tenant configuration: https ://[splunk hostname:port]/en-US/app/splunk_ta_o365/tenant
For Input Configuration: https ://[splunk hostname:port]/en-US/app/splunk_ta_o365/input
For logging and proxy settings: https: //[splunk hostname:port]/en-US/app/splunk_ta_o365/settings

0 Karma

marycordova
SplunkTrust
SplunkTrust

If you have access to an Azure environment there is a better way to get O365 logs by passing them through Azure than using an API based app: https://answers.splunk.com/answers/678660/how-to-get-logs-from-azure-and-o365-into-splunk.html

@marycordova
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...