All Apps and Add-ons

Microsoft Teams AddOn and Splunk Cloud

jasonabbott
Explorer

Hi, I'm trying to configure the Teams Add-on for Splunk (https://splunkbase.splunk.com/app/4994) on Splunk Cloud and I have gotten the UserReport working just fine, but none of the other data works.  I have created a WebHook pointing to idm-xx.splunkcloud.com to ingest the CDR data, but I have received no traffic into it.

I've granted all the privileges to the Azure App that are called for in the detailed directions.  

In fact, nothing but the User Reports are working.  Is there a step I'm missing?

 

Labels (1)
0 Karma
1 Solution

jasonabbott
Explorer

I got it resolved; apparently I need to learn to read better :). You can't install the Add-on in Splunk Cloud, it has to be on a heavy forwarder.  Once I did that and fixed the webhook (details here: https://community.splunk.com/t5/All-Apps-and-Add-ons/Ingesting-logs-from-Microsoft-Teams/m-p/506860/...), everything is working fine!  Thanks!

View solution in original post

Tags (3)
0 Karma

jasonabbott
Explorer

I got it resolved; apparently I need to learn to read better :). You can't install the Add-on in Splunk Cloud, it has to be on a heavy forwarder.  Once I did that and fixed the webhook (details here: https://community.splunk.com/t5/All-Apps-and-Add-ons/Ingesting-logs-from-Microsoft-Teams/m-p/506860/...), everything is working fine!  Thanks!

Tags (3)
0 Karma

biagiodipalma
Explorer

How do you extract fields at search time if the app is not installed in Splunk Cloud instance? 
I'm trying to ingest data from teams: my architecture has heavy forwarders that send data to Splunk Cloud.
 Does the HF index data before sending to cloud?

0 Karma

Bodach
Observer

The app can still be installed on the Splunk Cloud search head for the search time knowledge etc. You just can't use the webhook.

0 Karma

biagiodipalma
Explorer

In the end I had to edit the app manually because it was not accepted by Splunk AppInspect: I know that the app is useful for search time knowledge etc, but it's not compliant. 

This is my solution.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...