All Apps and Add-ons

Microsoft Graph Security API Add-on configuration issue

pateriaak
Explorer

I have just install Microsoft Graph Security API Add-on and set up Application / Accesses at Azure end, however when I go into the configuration tab to add a new account, I just see a loading scroll and dont see any button to "ADD" account config. Have anyone encounter the same? if so please share how you resolve it. 

Labels (2)
0 Karma
1 Solution

faizancool85
Path Finder

Looks like user running splunkd service doesn't have permission on "TA_microsoft_graph_security_add_on_for_splunk_rh_account.py" script, You can find this script under bin directory of the Graph Security addon.

Hope this solves your question 🙂

 

View solution in original post

faizancool85
Path Finder

I deployed it a couple of weeks back, I didn't face this issue.

What is the core version?  Graph API Version? and OS?

0 Karma

pateriaak
Explorer

What is the core version? 7.2.9.1

Graph API Version? 1.1.0

and OS? 3.10.0-514.el7.x86_64

0 Karma

faizancool85
Path Finder

Looks like user running splunkd service doesn't have permission on "TA_microsoft_graph_security_add_on_for_splunk_rh_account.py" script, You can find this script under bin directory of the Graph Security addon.

Hope this solves your question 🙂

 

pateriaak
Explorer

Thank you, I can see the option in config tab to add a new account. 

0 Karma

faizancool85
Path Finder

You're welcome! An upvote to the answer would be appreciated 🙂 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...