All Apps and Add-ons

Office 365 Email Tracking not detected by app Data Source Check

alastor
Path Finder

ms:o365:reporting:messagetrace isn't in the queries as a way to find email tracking details. Can we get an app update to cover that for email related detection?

Currently it appears to be looking for these: "sourcetype=cisco:esa* OR sourcetype=*:MessageTracking OR tag=email"

0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

Fixed in my dev environment! It will be published as 2.3.2, along with a few small bug fixes and a few minor enhancements to the bookmark page, targeting next week. (Hit me up on Splunk Usergroups Slack if you want early access!)

View solution in original post

David
Splunk Employee
Splunk Employee

Fixed in my dev environment! It will be published as 2.3.2, along with a few small bug fixes and a few minor enhancements to the bookmark page, targeting next week. (Hit me up on Splunk Usergroups Slack if you want early access!)

alastor
Path Finder

additionally, for Office 365 data collection for message traces, the data is delayed by at least 1440 minutes because, and this is from the app input configuration text, "Microsoft may delay trace events up to 24 hours. Specify how close to "now" a query may run (smaller values may introduce data loss for large volumes). See the README.md file for more information."

https://apps.splunk.com/apps/id/TA-MS_O365_Reporting

This means the -4 hours search default will likely not turn up results for Office 365 users.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...