All Apps and Add-ons

Microsoft Office 365 App for Splunk

nicktaitano
Explorer

App Veresion: 2.0.2
Splunk 7.x

Installed the Splunk App, configured the Azure/O365 accounts and I'm able to view data from services we're currently subscribed: OneDrive, Teams, Exchange but I'm not able to populate the 'Azure Active Directory' graph on the main app dashboard.

alt text

If I click on 'Azure AD' at the very top I'm able to view the Azure failed logons so I'm not sure why it's not populating the information on the main dashboard.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi nicktaitano,
the problem in in eventtypes and macros: there isn't the indication of Indexes.
You can test this anomaly opening the search of one panel in Search dashboard and adding the index=your_index filter to the main search.
You can solve this problem in two ways:

  • put the indexes in the default search path [ Settings -- Access Controls -- Roles -- -- Indexes];
  • create an eventtype with index=your_index and put this eventtype in each eventtype or macro of your App.

I prefer the second though it requests more work, because it's more clear and more performant.

Ciao.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...