All Apps and Add-ons

Microsoft Office 365 App for Splunk

nicktaitano
Explorer

App Veresion: 2.0.2
Splunk 7.x

Installed the Splunk App, configured the Azure/O365 accounts and I'm able to view data from services we're currently subscribed: OneDrive, Teams, Exchange but I'm not able to populate the 'Azure Active Directory' graph on the main app dashboard.

alt text

If I click on 'Azure AD' at the very top I'm able to view the Azure failed logons so I'm not sure why it's not populating the information on the main dashboard.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi nicktaitano,
the problem in in eventtypes and macros: there isn't the indication of Indexes.
You can test this anomaly opening the search of one panel in Search dashboard and adding the index=your_index filter to the main search.
You can solve this problem in two ways:

  • put the indexes in the default search path [ Settings -- Access Controls -- Roles -- -- Indexes];
  • create an eventtype with index=your_index and put this eventtype in each eventtype or macro of your App.

I prefer the second though it requests more work, because it's more clear and more performant.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Blueprints for High-Maturity Operations: Splunk Lantern Articles on SOAR, ES 8.4, ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...