App Veresion: 2.0.2
Splunk 7.x
Installed the Splunk App, configured the Azure/O365 accounts and I'm able to view data from services we're currently subscribed: OneDrive, Teams, Exchange but I'm not able to populate the 'Azure Active Directory' graph on the main app dashboard.
If I click on 'Azure AD' at the very top I'm able to view the Azure failed logons so I'm not sure why it's not populating the information on the main dashboard.
Hi nicktaitano,
the problem in in eventtypes and macros: there isn't the indication of Indexes.
You can test this anomaly opening the search of one panel in Search dashboard and adding the index=your_index
filter to the main search.
You can solve this problem in two ways:
index=your_index
and put this eventtype in each eventtype or macro of your App.I prefer the second though it requests more work, because it's more clear and more performant.
Ciao.
Giuseppe