All Apps and Add-ons

Message Trace - Splunk Add-On for Microsoft Office 365

Dallastek1
Path Finder
I have configured the microsoft 365 office 365, all are working except message trace. I rebuilt the input but still getting this error message when checking the internal logs. all other exchange mailbox data is coming in and all use the same acct.
Dallastek1_0-1748981615332.png
Labels (2)
0 Karma

Meett
Splunk Employee
Splunk Employee

Hello @Dallastek1 , Explanation given by @livehybrid is all correct here based on ERROR messages and screenshot it appears that you are missing required permissions, also make sure that you have given permission as App based and not Delegated one as they are not correct form of permissions.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Dallastek1 

I think you might need GlobalReader/Security Reader Roles for this API call,  check out the following Microsoft docs relating to this https://learn.microsoft.com/en-us/previous-versions/office/developer/o365-enterprise-developers/jj98...

In addition to the ReportingWebService.Read.All application permissions you have.

The following spreadsheet can be good at determining which permissions are used by different Microsoft/Azure/O365 TAs and worth having bookmarked! https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/edit?gid=0#gid=0

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Dallastek1
Path Finder

should have all the required permission unless there is something specific we missed

Dallastek1_0-1748981992346.png

 



0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...