All Apps and Add-ons

Message Trace - Splunk Add-On for Microsoft Office 365

Dallastek1
Path Finder
I have configured the microsoft 365 office 365, all are working except message trace. I rebuilt the input but still getting this error message when checking the internal logs. all other exchange mailbox data is coming in and all use the same acct.
Dallastek1_0-1748981615332.png
Labels (2)
0 Karma

Meett
Splunk Employee
Splunk Employee

Hello @Dallastek1 , Explanation given by @livehybrid is all correct here based on ERROR messages and screenshot it appears that you are missing required permissions, also make sure that you have given permission as App based and not Delegated one as they are not correct form of permissions.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Dallastek1 

I think you might need GlobalReader/Security Reader Roles for this API call,  check out the following Microsoft docs relating to this https://learn.microsoft.com/en-us/previous-versions/office/developer/o365-enterprise-developers/jj98...

In addition to the ReportingWebService.Read.All application permissions you have.

The following spreadsheet can be good at determining which permissions are used by different Microsoft/Azure/O365 TAs and worth having bookmarked! https://docs.google.com/spreadsheets/d/1YJAqNmcXZU-7O9CxVKupOkR6q2S8TXriMeLAUMYmMs4/edit?gid=0#gid=0

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Dallastek1
Path Finder

should have all the required permission unless there is something specific we missed

Dallastek1_0-1748981992346.png

 



0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...