Hi @wstarowicz, what errors do you have exactly in
_internal regarding this issue, could you give us some outputs here ?
It's a bit strange. Earlier I had 429 (since few days). These started to appear (as INFO) after few disabling/enabling of the input. Now it started working (logs are downloaded). So this is rather question now what does it mean.
2019-06-21 11:52:40,409 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): login.microsoftonline.com
2019-06-21 11:52:40,690 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_make_request:400 | https://login.microsoftonline.com:443 "POST /tenant_id/oauth2/v2.0/token HTTP/1.1" 200 1516
2019-06-21 11:52:40,693 DEBUG pid=11844 tid=MainThread file=base_modinput.py:log_debug:286 | Sign-in URL used: https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&$filter=createdDateTime+...
2019-06-21 11:52:40,693 INFO pid=11844 tid=MainThread file=setup_util.py:log_info:114 | Customized key can not be found
Which Splunk version are you using ? Maybe there was an incompatibility. Also did you restart Splunk after installing the ad-on ?
That should be okay, it's supported :
Splunk Versions: 7.3, 7.2, 7.1, 7.0, 6.6. Should be some bug that got flushed with the enable-disable.
Same issue here. My Client Certificate expired. I created a new one. Then may other errors, but this is the most pervasive.
tid=MainThread file=setuputil.py:loginfo:114 | Customized key can not be found