All Apps and Add-ons

Office 365 data import app: Why am I unable to view the Malware Detail Report?

billford
Path Finder

I tried to email the app author, but it bounced (well told me I wasn't allowed to send). I'm trying to pull down the malware detail report and when I try by hand, it's empty. Anyone know if there's a different REST endpoint than the one documented? I'm wondering if it's just broken and that's why it's not included in this app. Just a shot in the dark.

https://msdn.microsoft.com/EN-US/library/office/jj984330.aspx#sectionSection3

Thanks in advance.

Bill

Tags (1)
0 Karma
1 Solution

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

View solution in original post

0 Karma

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

0 Karma

billford
Path Finder

Well I meant even when I try to retrieve the malware report with a browser via the REST endpoint it is always empty, this is outside the 365 app. I was just wondering if there was some known problem with the endpoint.

If I knew how to write in .net I would totally contribute, I'm sorta porting this over to Python because most of my customers don't have Solunk on Windows.

Thanks

Bill

0 Karma

halr9000
Motivator

@billford, I converted your answer to a comment to keep the Q&A format.

halr9000
Motivator

Paging @gblock

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...