All Apps and Add-ons

Office 365 data import app: Why am I unable to view the Malware Detail Report?

billford
Path Finder

I tried to email the app author, but it bounced (well told me I wasn't allowed to send). I'm trying to pull down the malware detail report and when I try by hand, it's empty. Anyone know if there's a different REST endpoint than the one documented? I'm wondering if it's just broken and that's why it's not included in this app. Just a shot in the dark.

https://msdn.microsoft.com/EN-US/library/office/jj984330.aspx#sectionSection3

Thanks in advance.

Bill

Tags (1)
0 Karma
1 Solution

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

View solution in original post

0 Karma

julienjtpierre
Explorer

@billford
The reason you are not able to see the MailMalwareDetail report is because it is not yet supported by the Office 365 app for Splunk, even though it is available via the admin reporting web service.
We do not yet have commitments on adding this report, but the project is open source https://github.com/Microsoft/o365rwsclient and we accept contributions from anyone.
Having said that, we have one contributor that is looking at the Mail reports, so it might come soon.

Thanks. Julien

0 Karma

billford
Path Finder

Well I meant even when I try to retrieve the malware report with a browser via the REST endpoint it is always empty, this is outside the 365 app. I was just wondering if there was some known problem with the endpoint.

If I knew how to write in .net I would totally contribute, I'm sorta porting this over to Python because most of my customers don't have Solunk on Windows.

Thanks

Bill

0 Karma

halr9000
Motivator

@billford, I converted your answer to a comment to keep the Q&A format.

halr9000
Motivator

Paging @gblock

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...