All Apps and Add-ons

Office 365 data import app: Why am I unable to view the Malware Detail Report?

billford
Path Finder

I tried to email the app author, but it bounced (well told me I wasn't allowed to send). I'm trying to pull down the malware detail report and when I try by hand, it's empty. Anyone know if there's a different REST endpoint than the one documented? I'm wondering if it's just broken and that's why it's not included in this app. Just a shot in the dark.

https://msdn.microsoft.com/EN-US/library/office/jj984330.aspx#sectionSection3

Thanks in advance.

Bill

Tags (1)
0 Karma
1 Solution

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

View solution in original post

0 Karma

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

0 Karma

billford
Path Finder

Well I meant even when I try to retrieve the malware report with a browser via the REST endpoint it is always empty, this is outside the 365 app. I was just wondering if there was some known problem with the endpoint.

If I knew how to write in .net I would totally contribute, I'm sorta porting this over to Python because most of my customers don't have Solunk on Windows.

Thanks

Bill

0 Karma

halr9000
Motivator

@billford, I converted your answer to a comment to keep the Q&A format.

halr9000
Motivator

Paging @gblock

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...