All Apps and Add-ons

Microsoft Office 365 App for Splunk

nicktaitano
Explorer

App Veresion: 2.0.2
Splunk 7.x

Installed the Splunk App, configured the Azure/O365 accounts and I'm able to view data from services we're currently subscribed: OneDrive, Teams, Exchange but I'm not able to populate the 'Azure Active Directory' graph on the main app dashboard.

alt text

If I click on 'Azure AD' at the very top I'm able to view the Azure failed logons so I'm not sure why it's not populating the information on the main dashboard.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi nicktaitano,
the problem in in eventtypes and macros: there isn't the indication of Indexes.
You can test this anomaly opening the search of one panel in Search dashboard and adding the index=your_index filter to the main search.
You can solve this problem in two ways:

  • put the indexes in the default search path [ Settings -- Access Controls -- Roles -- -- Indexes];
  • create an eventtype with index=your_index and put this eventtype in each eventtype or macro of your App.

I prefer the second though it requests more work, because it's more clear and more performant.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...