All Apps and Add-ons

Office 365 data import app: Why am I unable to view the Malware Detail Report?

billford
Path Finder

I tried to email the app author, but it bounced (well told me I wasn't allowed to send). I'm trying to pull down the malware detail report and when I try by hand, it's empty. Anyone know if there's a different REST endpoint than the one documented? I'm wondering if it's just broken and that's why it's not included in this app. Just a shot in the dark.

https://msdn.microsoft.com/EN-US/library/office/jj984330.aspx#sectionSection3

Thanks in advance.

Bill

Tags (1)
0 Karma
1 Solution

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

View solution in original post

0 Karma

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

0 Karma

billford
Path Finder

Well I meant even when I try to retrieve the malware report with a browser via the REST endpoint it is always empty, this is outside the 365 app. I was just wondering if there was some known problem with the endpoint.

If I knew how to write in .net I would totally contribute, I'm sorta porting this over to Python because most of my customers don't have Solunk on Windows.

Thanks

Bill

0 Karma

halr9000
Motivator

@billford, I converted your answer to a comment to keep the Q&A format.

halr9000
Motivator

Paging @gblock

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...